cloudinary / cloudinary/cloudinary-react-native

Vulnerabilities in Package

Open
#25 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
28
Forks
21
PR merge metrics
No merged PRs in 30d

Description

## Bug report for Cloudinary React Native SDK
Before proceeding, please update to latest version and test if the issue persists

## Describe the bug in a sentence or two.

During install process, npm says there are 18 vulnerabilities (14 moderate, 4 high). It installs just fine, but I am a little less than thrilled to be adding it to my project.

## Issue Type (Can be multiple)
[ ] Build - Can’t install or import the SDK
[ ] Performance - Performance issues
[ ] Behaviour - Functions aren’t working as expected (Such as generate URL)
[ ] Documentation - Inconsistency between the docs and behaviour
[x] Other (Specify) - Security

## Steps to reproduce
Install package using npm

## Error screenshots or Stack Trace (if applicable)
![cloudinary install security issues](https://github.com/cloudinary/cloudinary-react-native/assets/79173587/2408958f-fb1c-4124-ba4b-380e7cbb6bdf)

## Build/Dependency management
[x] Cocoa-Pods
[ ] Carthage
[ ] Manual import
[x] Other (Specify) - npm

## Is the issue reproducible only on a specific device?
[x] No - not tested, but given the circumstances, I wouldn't think so
[ ] Yes (specify device model + iOS/Android version)

## Versions and Libraries (fill in the version numbers)
React Native Cloudinary SDK version - 1.0.0
OSX (on the dev environment) - 14.5

Repository
If possible, please provide a link to a reproducible repository that showcases the problem

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.