GeekyAnts / GeekyAnts/nativebase-templates
Possible Vulnerability: Please bump react native to 0.69
- Dominant language
- JavaScript
- Stars
- 73
- Forks
- 69
- PR merge metrics
- No merged PRs in 30d
Description
Please bump react native to 0.69
https://github.com/GeekyAnts/nativebase-templates/blob/master/nextjs-with-native-base-typescript/package.json#L17
Getting security [alert](https://github.com/advisories/GHSA-7mhc-prgv-r3q4) for transitive dependency hermes-engine
```
Vulnerability Found:
Severity: CRITICAL
Modules: @native-base/nextjs-template-typescript>react-native>hermes-engine
URL: https://github.com/advisories/GHSA-7mhc-prgv-r3q4
```
Contributor guide
No contributing guide indexed for this repository
Research direction
Start at nextjs-with-native-base-typescript/package.json line 17 and review the React Native dependency and its transitive hermes-engine alert. Update React Native to 0.69, then verify that the reported GHSA-7mhc-prgv-r3q4 vulnerability is no longer present in the template dependency tree.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- react-native
- Domain
- mobile, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100