Skip to content

[Snyk] Security upgrade react-native from 0.84.0 to 0.85.0#50

Merged
RhysAtBolt merged 3 commits intomainfrom
snyk-fix-9a3e3e241bbc8f1c67ae8d94dc629dea
Apr 7, 2026
Merged

[Snyk] Security upgrade react-native from 0.84.0 to 0.85.0#50
RhysAtBolt merged 3 commits intomainfrom
snyk-fix-9a3e3e241bbc8f1c67ae8d94dc629dea

Conversation

@snyk-io
Copy link
Copy Markdown
Contributor

@snyk-io snyk-io Bot commented Apr 7, 2026

Description

Bumps react-native from 0.84.0 to 0.85.0 in the example app to fix a medium-severity vulnerability (SNYK-JS-INFLIGHT-6095116: Missing Release of Resource after Effective Lifetime in the transitive `inflight` dependency).

This PR was originally created by Snyk. The `yarn.lock` has been updated to match.

Testing

  • Dependency-only change in the example app; no behaviour changes.
  • CI lint, typecheck, and test suite pass.

Security Review

Important

A security review is required for every PR in this repository to comply with PCI requirements.

  • I have considered and reviewed security implications of this PR and included the summary below.

Security Impact Summary

This PR upgrades a transitive dependency (inflight) that had a resource leak vulnerability. No payment flows, authentication logic, user data handling, or external integrations are changed. The upgrade only affects the example app's dependency tree, not the SDK itself.

@snyk-io snyk-io Bot requested review from a team as code owners April 7, 2026 20:17
@snyk-io
Copy link
Copy Markdown
Contributor Author

snyk-io Bot commented Apr 7, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

RhysAtBolt and others added 2 commits April 7, 2026 22:34
Regenerates the lockfile after Snyk bumped react-native from 0.84.0 to
0.85.0 in example/package.json. The previous commit only changed the
manifest; CI's hardened mode requires the lockfile to be in sync.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@RhysAtBolt RhysAtBolt merged commit 9915a14 into main Apr 7, 2026
7 of 8 checks passed
@RhysAtBolt RhysAtBolt deleted the snyk-fix-9a3e3e241bbc8f1c67ae8d94dc629dea branch April 7, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants