fix: added vulnerability fixes - #142
Open
DeepanshuAtStallion wants to merge 1 commit into
Open
DeepanshuAtStallion wants to merge 1 commit into
DeepanshuAtStallion wants to merge 1 commit into
Conversation
sherlock-stallion
requested changes
Sep 26, 2026
sherlock-stallion
left a comment
Contributor
There was a problem hiding this comment.
I have updated the semantic release package in new PR let it get merged and rebase before merging
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix the majority of open Dependabot dependency-vulnerability alerts (410 total) across all four lockfiles without any breaking API changes
Drop package-lock.json entirely — this project is yarn-only (CI, scripts, and .yarnrc all use yarn); the npm lockfiles were unused, had drifted out of sync with yarn.lock, and were doubling the Dependabot alert count
Bump semantic-release (dev-only, release-pipeline tooling) to pull in a patched bundled npm CLI
Fix an Android native-build issue (unrelated CMake incompatibility, found while verifying the app still runs)
Vulnerability fixes
Before: 410 open Dependabot alerts across package-lock.json, yarn.lock, example/package-lock.json, example/yarn.lock.
After: ~407 resolve; 3 remain open (details below).
Context: this package ships no runtime dependencies, only devDependencies — npm audit --omit=dev shows 0 vulnerabilities for consumers of react-native-stallion. Every flagged package was build/test/release tooling (jest, the RN CLI, semantic-release, eslint, etc.), not code that ships to users.
What was done:
yarn install refresh (yarn.lock, example/yarn.lock) — re-resolved transitive dependencies to the latest versions already satisfying existing semver ranges. No package.json range changes, no breaking bumps.
semantic-release 19.0.3 → 24.2.9 (package.json) — the old version bundled npm@8.19.4 internally via @semantic-release/npm, which accounted for most of the remaining high/critical findings (tar, pacote, brace-expansion, minimatch, ip, etc., all nested under node_modules/npm/...). v24 bundles npm@10.9.9 instead. Requires Node ≥20.8.1 — already satisfied by CI (actions/setup-node pins 20.x). This only affects the automated release/publish GitHub Action, nothing else.
Removed package-lock.json and example/package-lock.json, added package-lock.json to .gitignore. Verified nothing in the repo (CI, scripts, lefthook.yml, CONTRIBUTING.md) depends on npm lockfiles — CI only ever runs yarn install --frozen-lockfile. This alone closes ~204 alerts that existed purely because the same vulnerability was reported twice (once per lockfile).
3 alerts remain open, both blocked on major version bumps considered too large/risky for this PR:
fast-xml-parser (yarn.lock, example/yarn.lock) — fix requires React Native 0.71.7 → 0.87.1
pacote (yarn.lock) — fix requires semantic-release 25.x, which needs Node ≥22.14 (CI is on Node 20.x)
Both are flagged as intentional follow-up work, not fixed here.
Verification: yarn typecheck and yarn test pass after every change.
Other fixes
example/ios/Podfile.lock — was stale (pinned react-native-stallion@2.4.0-alpha.4), out of sync with the actually-installed Pods/ (2.4.2). Resynced so Xcode's "Check Pods Manifest.lock" build step doesn't fail. Pre-existing drift, unrelated to the dependency bumps above.
android/build.gradle — pinned cmake to version "3.22.1" in the externalNativeBuild block. Without it, AGP defaults to CMake 3.18.1, which the Android SDK only ships as an x86_64-only binary — this fails outright on Apple Silicon Macs without Rosetta installed. 3.22.1 ships as a universal (arm64 + x86_64) binary. Strict improvement: fixes native builds for Apple Silicon consumers, no effect on anyone else.
Test plan
yarn typecheck passes
yarn test passes
Example app builds and runs on iOS Simulator (Xcode build succeeded, JS bundle loads, SDK login screen renders)
Example app builds and runs on Android emulator (Gradle build succeeded, JS bundle loads, verified interactivity — tapped a button, SDK modal opened)
Verify an actual semantic-release --dry-run / real release against this branch before merging, since the release-pipeline bump (item 2) couldn't be fully exercised without live NPM/GitHub tokens
Confirm GitHub's Dependabot rescan closes the expected ~407 alerts after merge