You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
$npm audit fix --force
npm WARN using --force Recommended protections disabled.
npm WARN audit Updating react-native-unimodules to 0.14.10,which is a SemVer major change.
npm WARN deprecated [email protected]: replaced by the 'expo' package, learn more: https://blog.expo.dev/whats-new-in-expo-modules-infrastructure-7a7cdda81ebc
npm WARN deprecated @unimodules/[email protected]: replaced by the 'expo' package, learn more: https://blog.expo.dev/whats-new-in-expo-modules-infrastructure-7a7cdda81ebc
npm WARN deprecated @unimodules/[email protected]: replaced by the 'expo' package, learn more: https://blog.expo.dev/whats-new-in-expo-modules-infrastructure-7a7cdda81ebc
added 34 packages, removed 42 packages, changed 14 packages, and audited 3038 packages in 10s
169 packages are looking for funding
run `npm fund` for details
# npm audit report
ajv <6.12.3
Severity: moderate
Prototype Pollution in Ajv - https://github.com/advisories/GHSA-v88g-cgmw-v5xw
fix available via `npm audit fix`
node_modules/@expo/schemer/node_modules/ajv
@expo/schemer <=1.4.1
Depends on vulnerable versions of ajv
node_modules/@expo/schemer
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
ansi-html <0.0.8
Severity: high
Uncontrolled Resource Consumption in ansi-html - https://github.com/advisories/GHSA-whgm-jr23-g3j9
fix available via `npm audit fix`
node_modules/ansi-html
webpack-dev-server 2.0.0-beta - 4.7.2
Depends on vulnerable versions of ansi-html
Depends on vulnerable versions of chokidar
Depends on vulnerable versions of selfsigned
node_modules/webpack-dev-server
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
axios <0.21.2
Severity: high
Incorrect Comparison in axios - https://github.com/advisories/GHSA-cph5-m8f7-6c5x
fix available via `npm audit fix`
node_modules/axios
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
browserslist 4.0.0 - 4.16.4
Severity: moderate
Regular Expression Denial of Service in browserslist - https://github.com/advisories/GHSA-w8qv-6jwh-64r5
fix available via `npm audit fix`
node_modules/react-dev-utils/node_modules/browserslist
react-dev-utils 0.6.0-alpha.f55d2212 - 12.0.0-next.60
Depends on vulnerable versions of browserslist
Depends on vulnerable versions of immer
Depends on vulnerable versions of shell-quote
node_modules/react-dev-utils
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
glob-parent <5.1.2
Severity: high
glob-parent before 5.1.2 vulnerable to Regular Expression Denial of Service in enclosure regex - https://github.com/advisories/GHSA-ww39-953v-wcq6
fix available via `npm audit fix`
node_modules/webpack-dev-server/node_modules/glob-parent
chokidar 1.0.0-rc1 - 2.1.8
Depends on vulnerable versions of glob-parent
node_modules/webpack-dev-server/node_modules/chokidar
webpack-dev-server 2.0.0-beta - 4.7.2
Depends on vulnerable versions of ansi-html
Depends on vulnerable versions of chokidar
Depends on vulnerable versions of selfsigned
node_modules/webpack-dev-server
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
got <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97
fix available via `npm audit fix`
node_modules/is-reachable/node_modules/got
node_modules/package-json/node_modules/got
is-reachable 2.0.0 - 4.0.0
Depends on vulnerable versions of got
node_modules/is-reachable
package-json <=6.5.0
Depends on vulnerable versions of got
node_modules/package-json
latest-version 0.2.0 - 5.1.0
Depends on vulnerable versions of package-json
node_modules/latest-version
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
immer <9.0.6
Severity: critical
Prototype Pollution in immer - https://github.com/advisories/GHSA-33f9-j839-rf8h
fix available via `npm audit fix`
node_modules/immer
react-dev-utils 0.6.0-alpha.f55d2212 - 12.0.0-next.60
Depends on vulnerable versions of browserslist
Depends on vulnerable versions of immer
Depends on vulnerable versions of shell-quote
node_modules/react-dev-utils
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
node-forge <=1.2.1
Severity: high
Improper Verification of Cryptographic Signature in node-forge - https://github.com/advisories/GHSA-cfm4-qjh2-4765
URL parsing in node-forge could lead to undesired behavior. - https://github.com/advisories/GHSA-gf8q-jrpm-jvxq
fix available via `npm audit fix`
node_modules/selfsigned/node_modules/node-forge
node_modules/xdl/node_modules/node-forge
selfsigned 1.1.1 - 1.10.14
Depends on vulnerable versions of node-forge
node_modules/selfsigned
webpack-dev-server 2.0.0-beta - 4.7.2
Depends on vulnerable versions of ansi-html
Depends on vulnerable versions of chokidar
Depends on vulnerable versions of selfsigned
node_modules/webpack-dev-server
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
nth-check <2.0.1
Severity: high
Inefficient Regular Expression Complexity in nth-check - https://github.com/advisories/GHSA-rp65-9cf3-cjxr
fix available via `npm audit fix`
node_modules/svgo/node_modules/nth-check
css-select <=3.1.0
Depends on vulnerable versions of nth-check
node_modules/svgo/node_modules/css-select
svgo 1.0.0 - 1.3.2
Depends on vulnerable versions of css-select
node_modules/svgo
postcss-svgo 4.0.0-nightly.2020.1.9 - 5.0.0-rc.2
Depends on vulnerable versions of svgo
node_modules/postcss-svgo
cssnano-preset-default <=4.0.8
Depends on vulnerable versions of postcss-svgo
node_modules/cssnano-preset-default
cssnano 4.0.0-nightly.2020.1.9 - 4.1.11
Depends on vulnerable versions of cssnano-preset-default
node_modules/cssnano
optimize-css-assets-webpack-plugin 3.2.1 || 5.0.0 - 5.0.8
Depends on vulnerable versions of cssnano
node_modules/optimize-css-assets-webpack-plugin
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
shell-quote <=1.7.2
Severity: critical
Improper Neutralization of Special Elements used in a Command in Shell-quote - https://github.com/advisories/GHSA-g4rg-993r-mgx7
fix available via `npm audit fix`
node_modules/expo-cli/node_modules/shell-quote
node_modules/react-dev-utils/node_modules/shell-quote
node_modules/xdl/node_modules/shell-quote
@react-native-community/cli-tools 4.8.0 - 5.0.0-alpha.0 || 5.0.1-alpha.0 - 6.2.0
Depends on vulnerable versions of shell-quote
node_modules/expo-cli/node_modules/@react-native-community/cli-tools
node_modules/xdl/node_modules/@react-native-community/cli-tools
@react-native-community/cli-server-api <=5.0.1
Depends on vulnerable versions of @react-native-community/cli-tools
node_modules/expo-cli/node_modules/@react-native-community/cli-server-api
node_modules/xdl/node_modules/@react-native-community/cli-server-api
@expo/dev-server <=0.1.107
Depends on vulnerable versions of @react-native-community/cli-server-api
node_modules/expo-cli/node_modules/@expo/dev-server
node_modules/xdl/node_modules/@expo/dev-server
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
react-dev-utils 0.6.0-alpha.f55d2212 - 12.0.0-next.60
Depends on vulnerable versions of browserslist
Depends on vulnerable versions of immer
Depends on vulnerable versions of shell-quote
node_modules/react-dev-utils
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
tar <=4.4.17
Severity: high
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links - https://github.com/advisories/GHSA-qq89-hq3f-393p
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links - https://github.com/advisories/GHSA-9r2w-394v-53qc
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization - https://github.com/advisories/GHSA-3jfq-g458-7qm9
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning - https://github.com/advisories/GHSA-r628-mhmh-qjhw
fix available via `npm audit fix`
node_modules/xdl/node_modules/tar
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xmldom *
Severity: moderate
Misinterpretation of malicious XML input - https://github.com/advisories/GHSA-5fg8-2547-mr8q
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/xmldom
@expo/plist <=0.0.13
Depends on vulnerable versions of xmldom
node_modules/react-native-unimodules/node_modules/@expo/plist
@expo/config-plugins <=3.0.8
Depends on vulnerable versions of @expo/plist
node_modules/react-native-unimodules/node_modules/@expo/config-plugins
@expo/config 3.3.23-alpha.0 - 5.0.8
Depends on vulnerable versions of @expo/config-plugins
node_modules/react-native-unimodules/node_modules/@expo/config
expo-constants 10.1.2 - 11.1.0
Depends on vulnerable versions of @expo/config
node_modules/react-native-unimodules/node_modules/expo-constants
react-native-unimodules 0.13.2 - 0.15.0-alpha.0
Depends on vulnerable versions of expo-constants
node_modules/react-native-unimodules
37 vulnerabilities (1 low, 13 moderate, 15 high, 8 critical)
To address issues that do not require attention, run:
npm audit fix
To address all issues (including breaking changes), run:
npm audit fix --force
The text was updated successfully, but these errors were encountered:
The text was updated successfully, but these errors were encountered: