cloudinary / cloudinary/cloudinary-react-native
Vulnerabilities in Package
- 主要語言
- TypeScript
- 星號
- 28
- 分支
- 21
- PR 合併指標
- 30 天內沒有已合併 PR
描述
## Bug report for Cloudinary React Native SDK
Before proceeding, please update to latest version and test if the issue persists
## Describe the bug in a sentence or two.
During install process, npm says there are 18 vulnerabilities (14 moderate, 4 high). It installs just fine, but I am a little less than thrilled to be adding it to my project.
## Issue Type (Can be multiple)
[ ] Build - Can’t install or import the SDK
[ ] Performance - Performance issues
[ ] Behaviour - Functions aren’t working as expected (Such as generate URL)
[ ] Documentation - Inconsistency between the docs and behaviour
[x] Other (Specify) - Security
## Steps to reproduce
Install package using npm
## Error screenshots or Stack Trace (if applicable)

## Build/Dependency management
[x] Cocoa-Pods
[ ] Carthage
[ ] Manual import
[x] Other (Specify) - npm
## Is the issue reproducible only on a specific device?
[x] No - not tested, but given the circumstances, I wouldn't think so
[ ] Yes (specify device model + iOS/Android version)
## Versions and Libraries (fill in the version numbers)
React Native Cloudinary SDK version - 1.0.0
OSX (on the dev environment) - 14.5
Repository
If possible, please provide a link to a reproducible repository that showcases the problem
貢獻指南
研究方向
Start by installing version 1.0.0 with npm and auditing the dependency tree to identify which packages produce the 18 reported vulnerabilities. Confirm whether the findings affect runtime dependencies, then define done as resolving the applicable vulnerabilities without breaking the React Native SDK.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- react-native, typescript
- 領域
- mobile-dev, security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 停滯
- 描述清晰度
- 需要釐清
- 新手友好度
- 25/100