Skip to content

fix: added vulnerability fixes - #142

Open
DeepanshuAtStallion wants to merge 1 commit into
mainfrom
r/release.09.20.2026.vulnerabilities-fix
Open

DeepanshuAtStallion wants to merge 1 commit into
mainfrom
r/release.09.20.2026.vulnerabilities-fix

Conversation

@DeepanshuAtStallion

Copy link
Copy Markdown

Summary
Fix the majority of open Dependabot dependency-vulnerability alerts (410 total) across all four lockfiles without any breaking API changes
Drop package-lock.json entirely — this project is yarn-only (CI, scripts, and .yarnrc all use yarn); the npm lockfiles were unused, had drifted out of sync with yarn.lock, and were doubling the Dependabot alert count
Bump semantic-release (dev-only, release-pipeline tooling) to pull in a patched bundled npm CLI
Fix an Android native-build issue (unrelated CMake incompatibility, found while verifying the app still runs)
Vulnerability fixes
Before: 410 open Dependabot alerts across package-lock.json, yarn.lock, example/package-lock.json, example/yarn.lock.
After: ~407 resolve; 3 remain open (details below).

Context: this package ships no runtime dependencies, only devDependencies — npm audit --omit=dev shows 0 vulnerabilities for consumers of react-native-stallion. Every flagged package was build/test/release tooling (jest, the RN CLI, semantic-release, eslint, etc.), not code that ships to users.

What was done:

yarn install refresh (yarn.lock, example/yarn.lock) — re-resolved transitive dependencies to the latest versions already satisfying existing semver ranges. No package.json range changes, no breaking bumps.
semantic-release 19.0.3 → 24.2.9 (package.json) — the old version bundled npm@8.19.4 internally via @semantic-release/npm, which accounted for most of the remaining high/critical findings (tar, pacote, brace-expansion, minimatch, ip, etc., all nested under node_modules/npm/...). v24 bundles npm@10.9.9 instead. Requires Node ≥20.8.1 — already satisfied by CI (actions/setup-node pins 20.x). This only affects the automated release/publish GitHub Action, nothing else.
Removed package-lock.json and example/package-lock.json, added package-lock.json to .gitignore. Verified nothing in the repo (CI, scripts, lefthook.yml, CONTRIBUTING.md) depends on npm lockfiles — CI only ever runs yarn install --frozen-lockfile. This alone closes ~204 alerts that existed purely because the same vulnerability was reported twice (once per lockfile).
3 alerts remain open, both blocked on major version bumps considered too large/risky for this PR:

fast-xml-parser (yarn.lock, example/yarn.lock) — fix requires React Native 0.71.7 → 0.87.1
pacote (yarn.lock) — fix requires semantic-release 25.x, which needs Node ≥22.14 (CI is on Node 20.x)
Both are flagged as intentional follow-up work, not fixed here.

Verification: yarn typecheck and yarn test pass after every change.

Other fixes
example/ios/Podfile.lock — was stale (pinned react-native-stallion@2.4.0-alpha.4), out of sync with the actually-installed Pods/ (2.4.2). Resynced so Xcode's "Check Pods Manifest.lock" build step doesn't fail. Pre-existing drift, unrelated to the dependency bumps above.
android/build.gradle — pinned cmake to version "3.22.1" in the externalNativeBuild block. Without it, AGP defaults to CMake 3.18.1, which the Android SDK only ships as an x86_64-only binary — this fails outright on Apple Silicon Macs without Rosetta installed. 3.22.1 ships as a universal (arm64 + x86_64) binary. Strict improvement: fixes native builds for Apple Silicon consumers, no effect on anyone else.
Test plan
yarn typecheck passes
yarn test passes
Example app builds and runs on iOS Simulator (Xcode build succeeded, JS bundle loads, SDK login screen renders)
Example app builds and runs on Android emulator (Gradle build succeeded, JS bundle loads, verified interactivity — tapped a button, SDK modal opened)
Verify an actual semantic-release --dry-run / real release against this branch before merging, since the release-pipeline bump (item 2) couldn't be fully exercised without live NPM/GitHub tokens
Confirm GitHub's Dependabot rescan closes the expected ~407 alerts after merge

@sherlock-stallion sherlock-stallion left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have updated the semantic release package in new PR let it get merged and rebase before merging

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants