Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[expo] Upgrade react-native-reanimated to 3.10.0 #28561

Merged
merged 4 commits into from
May 1, 2024

Conversation

lukmccall
Copy link
Contributor

Why

Upgrades react-native-reanimated to 3.10.0

Test Plan

  • Expo Go ✅
  • Bare expo ✅

@expo-bot expo-bot added the bot: passed checks ExpoBot has nothing to complain about label May 1, 2024
@expo-bot
Copy link
Collaborator

expo-bot commented May 1, 2024

The Pull Request introduced fingerprint changes against the base commit: 87bd0df

Fingerprint diff
[
  {
    "type": "dir",
    "filePath": "ios",
    "reasons": [
      "bareNativeDir"
    ],
    "hash": "31a143318c0a538792f0de49e5741bab6b8f4118"
  }
]

Generated by PR labeler 🤖

@@ -2399,7 +2399,7 @@ SPEC CHECKSUMS:
GoogleDataTransport: 54dee9d48d14580407f8f5fbf2f496e92437a2f2
GoogleMaps: 032f676450ba0779bd8ce16840690915f84e57ac
GoogleUtilities: 13e2c67ede716b8741c7989e26893d151b2b2084
hermes-engine: 118ab4d39602f2b05fd37ba7356343d2b5344b9c
hermes-engine: 1d242e1d7d6c63ee223040c5a0d72d59105ed811
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this hash is not correct. It seems to be unstable again... 😢 Probably better to just revert this change.

Copy link

socket-security bot commented May 1, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@apidevtools/json-schema-ref-parser@11.6.0 filesystem, network Transitive: environment +3 1.02 MB philsturgeon
npm/@babel/code-frame@7.24.2 environment +9 179 kB nicolo-ribaudo
npm/@babel/core@7.24.4 environment, filesystem, unsafe +18 2.69 MB nicolo-ribaudo
npm/@babel/generator@7.24.4 None +1 525 kB nicolo-ribaudo
npm/@babel/helper-module-imports@7.24.3 None 0 63.8 kB nicolo-ribaudo
npm/@babel/helper-plugin-utils@7.24.0 None 0 11.7 kB nicolo-ribaudo
npm/@babel/parser@7.24.4 None 0 1.88 MB nicolo-ribaudo
npm/@babel/runtime@7.24.4 None 0 262 kB nicolo-ribaudo
npm/@babel/template@7.24.0 None 0 68.9 kB nicolo-ribaudo
npm/@babel/types@7.24.0 environment +2 2.49 MB nicolo-ribaudo
npm/@emotion/jest@11.11.0 environment +2 135 kB emotion-release-bot
npm/@emotion/react@11.11.4 environment Transitive: filesystem +14 1.14 MB emotion-release-bot
npm/@emotion/serialize@1.1.4 environment +5 1.34 MB emotion-release-bot
npm/@eslint-community/eslint-utils@4.4.0 None 0 379 kB eslint-community-bot
npm/@eslint-community/regexpp@4.10.0 None 0 431 kB eslint-community-bot
npm/@expo/styleguide-base@1.0.1 None +1 237 kB simek
npm/@expo/styleguide-icons@1.0.8 None 0 6.48 MB simek
npm/@expo/styleguide-search-ui@1.0.4 network +1 105 kB simek
npm/@expo/styleguide@8.2.2 None 0 88 kB simek
npm/@floating-ui/utils@0.2.1 None 0 72.7 kB atomiks
npm/@istanbuljs/schema@0.1.3 None 0 17.2 kB coreyfarrell
npm/@jridgewell/sourcemap-codec@1.4.15 None 0 45.9 kB jridgewell
npm/@jridgewell/trace-mapping@0.3.25 None +1 222 kB jridgewell
npm/@mdx-js/loader@2.3.0 Transitive: filesystem, network +1 239 kB wooorm
npm/@mdx-js/mdx@2.3.0 environment +16 693 kB wooorm
npm/@mdx-js/react@2.3.0 None +1 24.4 kB wooorm
npm/@nodelib/fs.stat@2.0.5 filesystem 0 11.8 kB mrmlnc
npm/@nodelib/fs.walk@1.2.8 Transitive: filesystem +2 90.5 kB mrmlnc
npm/@octokit/request-error@2.1.0 None 0 21.9 kB octokitbot
npm/@octokit/request@5.6.3 network +2 183 kB octokitbot
npm/@octokit/rest@18.12.0 None +7 1.77 MB octokitbot
npm/@octokit/types@6.41.0 None +1 2.31 MB octokitbot
npm/@ocular-d/vale-bin@2.29.6 filesystem, shell Transitive: environment, network +37 457 kB ocular-d
npm/@radix-ui/react-dialog@1.0.5 None +16 561 kB benoitgrelard
npm/@radix-ui/react-dropdown-menu@1.0.0 None +29 1.51 MB benoitgrelard
npm/@radix-ui/react-tooltip@1.0.7 None +22 1.04 MB benoitgrelard
npm/@reach/tabs@0.18.0 environment +6 3.51 MB chancestrickland
npm/@sentry/react@7.112.1 Transitive: network +12 11.4 MB sentry-bot
npm/@tailwindcss/typography@0.5.12 None +3 175 kB adamwathan
npm/@testing-library/jest-dom@6.4.2 Transitive: environment, eval, filesystem, network, shell, unsafe +63 2.82 MB testing-library-bot
npm/@testing-library/react-hooks@8.0.1 None 0 138 kB testing-library-bot
npm/@testing-library/react@15.0.3 environment +4 7.17 MB testing-library-bot
npm/@testing-library/user-event@14.5.2 Transitive: environment +4 3.3 MB testing-library-bot
npm/@types/babel__traverse@7.20.5 None 0 84.1 kB types
npm/@types/estree@1.0.5 None 0 25.7 kB types
npm/@types/fs-extra@11.0.4 None +1 42.5 kB types
npm/@types/google.analytics@0.0.46 None 0 30.2 kB types
npm/@types/gtag.js@0.0.19 None 0 8.85 kB types
npm/@types/hast@2.3.10 None 0 6.11 kB types
npm/@types/istanbul-lib-coverage@2.0.6 None 0 5.45 kB types
npm/@types/jest@29.5.12 None +2 527 kB types
npm/@types/json-schema@7.0.15 None 0 31.7 kB types
npm/@types/lodash@4.17.0 None 0 862 kB types
npm/@types/node@20.12.7 None 0 2.03 MB types
npm/@types/nprogress@0.2.3 None 0 4.83 kB types
npm/@types/prismjs@1.26.3 None 0 19.2 kB types
npm/@types/prop-types@15.7.12 None 0 6.71 kB types
npm/@types/react-dom@18.2.25 None 0 34.9 kB types
npm/@types/react@18.2.79 None +1 1.68 MB types
npm/@types/unist@2.0.10 None 0 8.56 kB types
npm/@typescript-eslint/eslint-plugin@7.7.1 Transitive: filesystem +12 5.35 MB jameshenry
npm/@typescript-eslint/parser@7.7.1 Transitive: filesystem +9 1.43 MB jameshenry
npm/@ungap/structured-clone@1.2.0 None 0 26.2 kB webreflection
npm/acorn-jsx@5.3.2 None 0 24.4 kB rreverser
npm/acorn@8.11.3 None 0 531 kB marijn
npm/agent-base@6.0.2 None 0 34.6 kB tootallnate
npm/anymatch@3.1.3 None 0 9.65 kB phated
npm/arg@5.0.2 None 0 13.7 kB leerobinson
npm/aria-query@5.3.0 None 0 192 kB jessebeach
npm/array-includes@3.1.8 None +1 35.5 kB ljharb
npm/array.prototype.flat@1.3.2 None 0 18.7 kB ljharb
npm/autoprefixer@10.4.19 environment +1 285 kB ai
npm/axios@1.6.8 network Transitive: filesystem +4 1.93 MB jasonsaayman
npm/bare-events@2.2.2 None 0 18.9 kB kasperisager
npm/bare-path@2.1.1 None +1 351 kB kasperisager
npm/braces@3.0.2 None +1 65.6 kB doowb
npm/browserslist@4.23.0 environment, filesystem +1 349 kB ai
npm/call-bind@1.0.7 None +2 65.3 kB ljharb
npm/caniuse-lite@1.0.30001612 None 0 2.05 MB caniuse-lite
npm/chalk@4.1.2 None 0 35 kB sindresorhus
npm/chokidar@3.6.0 environment, filesystem +3 110 kB paulmillr
npm/clipboard-copy@4.0.1 None 0 6.6 kB feross
npm/clone-response@1.0.2 None 0 4.61 kB lukechilds
npm/cmdk@0.2.1 None +3 242 kB paco
npm/cross-spawn@7.0.3 environment, filesystem, shell 0 21.2 kB satazor
npm/danger@11.3.1 Transitive: environment, eval, filesystem, network +59 6.21 MB orta
npm/date-fns@2.30.0 None 0 6.69 MB kossnocorp
npm/debug@4.3.4 environment 0 42.4 kB qix
npm/decode-uri-component@0.2.2 None 0 6.09 kB samverschueren
npm/decompress-tar@4.1.1 None +2 25.1 kB kevva
npm/define-data-property@1.1.4 None +2 50.4 kB ljharb
npm/define-properties@1.2.1 None 0 12.9 kB ljharb
npm/deprecation@2.3.1 None 0 4.01 kB gr2m
npm/dequal@2.0.3 None 0 14.2 kB lukeed
npm/end-of-stream@1.4.4 None 0 6.23 kB mafintosh
npm/error-ex@1.3.2 None +1 13.1 kB qix
npm/es-abstract@1.23.3 None +20 2.74 MB ljharb
npm/es-errors@1.3.0 None 0 12.3 kB ljharb
npm/es-iterator-helpers@1.0.18 None +5 255 kB ljharb
npm/es-shim-unscopables@1.0.2 None 0 11 kB ljharb
npm/escodegen@2.1.0 None +2 964 kB michaelficarra
npm/eslint-config-next@14.0.4 unsafe Transitive: filesystem +14 5.53 MB vercel-release-bot
npm/eslint-config-universe@12.0.1 Transitive: filesystem +7 1.06 MB tsapeta
npm/eslint-import-resolver-node@0.3.9 Transitive: environment +1 58.5 kB ljharb
npm/eslint-module-utils@2.8.1 None 0 51.1 kB ljharb
npm/eslint-plugin-import@2.29.1 filesystem, unsafe +5 1.43 MB ljharb
npm/eslint-plugin-lodash@7.4.0 filesystem 0 320 kB idok
npm/eslint-plugin-react-hooks@4.6.0 environment 0 118 kB gnoff
npm/eslint-plugin-react@7.34.1 filesystem Transitive: environment +7 1.09 MB ljharb
npm/eslint-plugin-tailwindcss@3.15.1 None 0 210 kB francoismassart
npm/eslint-plugin-testing-library@6.2.2 filesystem Transitive: environment +11 2.3 MB testing-library-bot
npm/eslint-visitor-keys@3.4.3 None 0 32.3 kB eslintbot
npm/eslint@8.57.0 environment, filesystem Transitive: eval, unsafe +32 7.81 MB eslintbot
npm/espree@9.6.1 None 0 73.6 kB eslintbot
npm/esprima@4.0.1 None 0 314 kB ariya
npm/estraverse@5.3.0 None 0 37.1 kB michaelficarra
npm/expect@29.7.0 Transitive: environment +16 990 kB simenb
npm/fast-deep-equal@3.1.3 None 0 13 kB esp
npm/fast-fifo@1.3.2 None 0 5.07 kB mafintosh
npm/fast-glob@3.3.2 filesystem 0 96.7 kB mrmlnc
npm/fast-json-stable-stringify@2.1.0 None 0 17 kB esp
npm/follow-redirects@1.15.6 network 0 29.4 kB rubenverborgh
npm/framer-motion@11.1.7 environment 0 2.23 MB popmotion
npm/front-matter@4.0.2 Transitive: environment, filesystem +1 128 kB jxson
npm/fs-extra@11.2.0 Transitive: filesystem +1 74.7 kB ryanzim
npm/fsevents@2.3.3 None 0 173 kB pipobscure
npm/function.prototype.name@1.1.6 None +1 42.2 kB ljharb
npm/get-intrinsic@1.2.4 eval +1 73.1 kB ljharb
npm/get-stream@3.0.0 None 0 7.88 kB sindresorhus
npm/github-slugger@2.0.0 None 0 15.9 kB wooorm
npm/glob@7.1.7 filesystem Transitive: environment +2 73.1 kB isaacs
npm/graceful-fs@4.2.11 environment, filesystem 0 32.5 kB isaacs
npm/has-bigints@1.0.2 None 0 12.8 kB ljharb
npm/has-property-descriptors@1.0.2 None +1 22.7 kB ljharb
npm/has-proto@1.0.3 None 0 12 kB ljharb
npm/has-symbols@1.0.3 None 0 20.6 kB ljharb
npm/has-tostringtag@1.0.2 None 0 17.6 kB ljharb
npm/hasown@2.0.2 None +1 40.2 kB ljharb
npm/hoist-non-react-statics@3.3.2 Transitive: environment +1 62.8 kB mridgway
npm/homedir-polyfill@1.0.3 environment, filesystem 0 8.05 kB doowb
npm/http-server@14.1.1 environment, filesystem, network +8 645 kB thornjad
npm/ignore@5.3.1 None 0 51.5 kB kael
npm/import-fresh@3.3.0 None 0 4.87 kB sindresorhus
npm/inherits@2.0.4 None 0 3.96 kB isaacs
npm/ini@1.3.8 None 0 9.3 kB isaacs
npm/is-callable@1.2.7 None 0 28.9 kB ljharb
npm/is-core-module@2.13.1 None 0 30.2 kB ljharb
npm/is-date-object@1.0.5 None 0 20.8 kB ljharb
npm/is-glob@4.0.3 None +1 19.8 kB phated
npm/is-shared-array-buffer@1.0.3 None 0 18.7 kB ljharb
npm/is-string@1.0.7 None 0 19.1 kB ljharb
npm/is-symbol@1.0.4 None 0 22 kB ljharb
npm/istanbul-lib-coverage@3.2.2 None 0 34.4 kB oss-bot
npm/jest-environment-jsdom@29.7.0 Transitive: environment, eval, filesystem, network, shell, unsafe +37 4.6 MB simenb
npm/jest@29.7.0 Transitive: environment, eval, filesystem, network, shell, unsafe +118 4.56 MB simenb
npm/js-tokens@4.0.0 None 0 15.1 kB lydell
npm/json5@2.2.3 None 0 235 kB jordanbtucker
npm/jsx-ast-utils@3.3.5 None 0 236 kB ljharb
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/loose-envify@1.4.0 environment 0 5.81 kB zertosh
npm/make-dir@1.3.0 filesystem 0 6.53 kB sindresorhus
npm/mdast-util-from-markdown@1.3.1 None +6 384 kB wooorm
npm/mdast-util-to-markdown@1.5.0 None +3 176 kB wooorm
npm/mdast-util-to-string@3.2.0 None +1 23.7 kB wooorm
npm/merge2@1.4.1 None 0 8.9 kB zensh
npm/micromark-core-commonmark@1.1.0 None +2 333 kB wooorm

🚮 Removed packages: npm/@react-navigation/bottom-tabs@6.4.3, npm/@react-navigation/native@6.0.16, npm/babel-preset-expo@11.0.3, npm/dedent@0.7.0, npm/expo-2d-context@0.0.4, npm/expo-apple-authentication@6.4.1, npm/expo-audio@0.1.0, npm/expo-auth-session@5.5.1, npm/expo-av@14.0.2, npm/expo-background-fetch@12.0.1, npm/expo-barcode-scanner@13.0.1, npm/expo-battery@8.0.1, npm/expo-blur@13.0.1, npm/expo-brightness@12.0.1, npm/expo-calendar@13.0.2, npm/expo-camera@15.0.3, npm/expo-cellular@6.0.1, npm/expo-checkbox@3.0.0, npm/expo-clipboard@6.0.2, npm/expo-contacts@13.0.2, npm/expo-crypto@13.0.2, npm/expo-device@6.0.1, npm/expo-document-picker@12.0.1, npm/expo-face-detector@12.7.1, npm/expo-file-system@17.0.1, npm/expo-font@12.0.4, npm/expo-gl@14.0.2, npm/expo-haptics@13.0.1, npm/expo-image-manipulator@12.0.2, npm/expo-image-picker@15.0.3, npm/expo-image@1.12.4, npm/expo-insights@0.7.0, npm/expo-intent-launcher@11.0.1, npm/expo-keep-awake@13.0.1, npm/expo-linking@6.3.1, npm/expo-local-authentication@14.0.1, npm/expo-localization@15.0.1, npm/expo-location@17.0.1, npm/expo-mail-composer@13.0.1, npm/expo-maps@0.4.0, npm/expo-media-library@16.0.3, npm/expo-module-scripts@3.5.1, npm/expo-modules-test-core@0.18.0, npm/expo-navigation-bar@3.0.2, npm/expo-network-addons@0.6.0, npm/expo-network@6.0.1, npm/expo-notifications@0.28.1, npm/expo-print@13.0.1, npm/expo-random@14.0.1, npm/expo-splash-screen@0.27.2, npm/expo-status-bar@1.12.1, npm/expo-store-review@7.0.1, npm/expo-task-manager@11.8.1, npm/expo-web-browser@13.0.3, npm/graphql@15.8.0, npm/immutable@4.3.5, npm/path-to-regexp@1.8.0, npm/react-dom@18.2.0, npm/react-native-paper@4.12.8, npm/react@18.2.0, npm/test-suite@1.0.0

View full report↗︎

Copy link

socket-security bot commented May 1, 2024

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Install scripts npm/@ocular-d/vale-bin@2.29.6
  • Install script: postinstall
  • Source: node lib/install.js
Install scripts npm/core-js@3.37.0
  • Install script: postinstall
  • Source: node -e "try{require('./postinstall')}catch(e){}"

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/@ocular-d/vale-bin@2.29.6
  • @SocketSecurity ignore npm/core-js@3.37.0

@brentvatne brentvatne merged commit 0dad9b1 into main May 1, 2024
19 of 21 checks passed
@brentvatne brentvatne deleted the @lukmccall/reanimated/bum-to-3.10 branch May 1, 2024 21:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bot: fingerprint changed bot: passed checks ExpoBot has nothing to complain about
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants