[Snyk] Upgrade react-native from 0.63.3 to 0.70.0 #752
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade react-native from 0.63.3 to 0.70.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-SHELLQUOTE-1766506
Why? Has a fix available, CVSS 8.1
SNYK-JS-REACTNATIVE-1298632
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1727253
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1309667
Why? Has a fix available, CVSS 8.1
SNYK-JS-WS-1296835
Why? Has a fix available, CVSS 8.1
SNYK-JS-SIMPLEPLIST-2413671
Why? Has a fix available, CVSS 8.1
SNYK-JS-NODEFETCH-674311
Why? Has a fix available, CVSS 8.1
SNYK-JS-NODEFETCH-2342118
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-629748
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-629268
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-608850
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-2342071
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1015406
Why? Has a fix available, CVSS 8.1
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react-native
0.70 stable is out!
This release includes 493 commits with 88 contributors! Thank you to all our contributors new and old! See the highlights of the release in our release blog post.
You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Changed
Android specific
android/app/.cxx
(542d43df9d by @ leotm)Fixed
.d.ts
files (0f0d52067c by @ tido64)You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Help us testing 🧪
RC4 is going to be the last RC before 0.70.0 - unless blocking issues arise. To help us catch them, test it by running:
And play around with the fresh app - let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one!
Changed
Android specific
iOS specific
Fixed
Android specific
You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Help us testing 🧪
To test it, run:
And play around with the fresh app - let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one!
To try it, run:
npx react-native init RN070RC2 --version 0.70.0-rc.2
You can participate in the conversation on the status of this release in the working group
To help you upgrade to this version, you can use the upgrade helper ⚛️
The full list of changes in release can read in the changelog PR
Help us testing 🧪
We need your help testing one feature in particular with this RC (autolinking of TurboModules from libraries)! Here is what you have to do:
cd ios
bundle install && RCT_NEW_ARCH_ENABLED=1 bundle exec pod install
(orRCT_NEW_ARCH_ENABLED=1 pod install
)cd ..
yarn ios
gradle.properties
true
yarn android
LOG Running "RN070RC1" with {"fabric":true,"initialProps":{"concurrentRoot":true},"rootTag":1}
yarn add <lib>
RCT_NEW_ARCH_ENABLED=1 pod install
for iOS), verify that the lib added works correctlyandroid/app/build/generated/rncli/src/main/jni/Android-rncli.mk
that there's a reference to the library added, something along the lines ofinclude <path>/node_modules/react-native-safe-area-context/android/build/generated/source/codegen/jni/Android.mk
import-codegen-modules :=
libreact_codegen_safeareacontext
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one - or use a different library that is already leveraging the new architecture!
To test it, run:
npx react-native init RN070RC1 --version 0.70.0-rc.1
You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Changed
Android specific
Fixed
.d.ts
files (0f0d52067c by @ tido64)You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file
Changed
Android specific
You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Changed
Android specific
Fixed
Android specific
You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Commit messages
Package name: react-native
.d.ts
files facebook/react-native#34439)android/app/.cxx
facebook/react-native#34430)helloworld_appmodules
facebook/react-native#34417).exe
to hermesc binary path for Windows users facebook/react-native#34151)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs