This repository was archived by the owner on May 20, 2025. It is now read-only.
This repository was archived by the owner on May 20, 2025. It is now read-only.
vm2 is still in 3.9.17, safe version is >=3.9.18 #2542
Closed
Description
Steps to Reproduce
- Install latest 8.0.2
yarn why vm2
(reports 3.9.17)- follow dep chain, at the end is react-native-code-push
Expected Behavior
What you expected to happen?
That the dependency is updated
Actual Behavior
What actually happens?
Dependency with security issues is not updated
Reproducible Demo
Install latest 8.0.2
and check the dependency chain

Environment
- react-native-code-push version: 8.0.2
- react-native version: yes
- iOS/Android/Windows version: yes
- Does this reproduce on a debug build or release build? yes
- Does this reproduce on a simulator, or only on a physical device? yes
Metadata
Metadata
Assignees
Labels
No labels