fix(deps): update dependency react-native-document-picker to v8.2.2 [security] #1872
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
8.1.3
->8.2.2
GitHub Vulnerability Alerts
CVE-2024-25466
Directory Traversal vulnerability in React Native Document Picker before 8.2.2 and 9.x before 9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.
Release Notes
rnmods/react-native-document-picker (react-native-document-picker)
v8.2.2
Compare Source
What's Changed
This is the fix present in v9 backported to v8.
Please note the vulnerability was reported by @FixedOctocat - Thank you!
v8.2.1
Compare Source
Full Changelog: react-native-documents/document-picker@v8.2.0...v8.2.1
v8.2.0
Compare Source
What's Changed
New Contributors
Full Changelog: react-native-documents/document-picker@v8.1.4...v8.2.0
v8.1.4
Compare Source
What's Changed
fix(android): DocumentPicker throw error Error: User canceled docume… by @GaryOoi in https://github.com/rnmods/react-native-document-picker/pull/630
chore(deps): bump minimatch from 3.0.4 to 3.1.2 by @dependabot in https://github.com/rnmods/react-native-document-picker/pull/605
chore(deps): bump json5 from 2.2.0 to 2.2.3 by @dependabot in https://github.com/rnmods/react-native-document-picker/pull/616
chore(deps): bump qs from 6.10.1 to 6.11.0 by @dependabot in https://github.com/rnmods/react-native-document-picker/pull/610
chore(deps): bump decode-uri-component from 0.2.0 to 0.2.2 by @dependabot in https://github.com/rnmods/react-native-document-picker/pull/609
chore(deps): bump http-cache-semantics from 4.1.0 to 4.1.1 by @dependabot in https://github.com/rnmods/react-native-document-picker/pull/625
chore(deps): bump @sideway/formula from 3.0.0 to 3.0.1 by @dependabot in https://github.com/rnmods/react-native-document-picker/pull/637
New Contributors
Full Changelog: react-native-documents/document-picker@v8.1.3...v8.1.4
Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.