Skip to content
This repository was archived by the owner on May 20, 2025. It is now read-only.
This repository was archived by the owner on May 20, 2025. It is now read-only.

vm2 is still in 3.9.17, safe version is >=3.9.18 #2542

Closed
@Grohden

Description

@Grohden

Steps to Reproduce

  1. Install latest 8.0.2
  2. yarn why vm2 (reports 3.9.17)
  3. follow dep chain, at the end is react-native-code-push

Expected Behavior

What you expected to happen?

That the dependency is updated

Actual Behavior

What actually happens?

Dependency with security issues is not updated

Reproducible Demo

Install latest 8.0.2

and check the dependency chain

Screenshot 2023-07-05 at 17 26 46

Environment

  • react-native-code-push version: 8.0.2
  • react-native version: yes
  • iOS/Android/Windows version: yes
  • Does this reproduce on a debug build or release build? yes
  • Does this reproduce on a simulator, or only on a physical device? yes

maybe related PRs #2519 #2517
maybe related issue #2489

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions