Skip to content

fix(deps): vuln uuid (major → 14.0.1) [packages/react-native-babel-plugin] - #1357

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/major/npm/react-native-babel-plugin/2-1785769460
Open

fix(deps): vuln uuid (major → 14.0.1) [packages/react-native-babel-plugin]#1357
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/major/npm/react-native-babel-plugin/2-1785769460

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • packages/react-native-babel-plugin (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
uuid 8.3.2 14.0.1 major Direct 3 MEDIUM

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

ℹ️ Other Vulnerabilities (3)
Package CVE Severity Summary Unsafe Version Fixed In Case
uuid GHSA-w5hq-g745-h8pq MODERATE uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided 8.3.2 11.1.1 -
uuid CVE-2026-41907 MODERATE uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided 8.3.2 - -
uuid CVE-2026-41988 MODERATE - 8.3.2 - -

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

This PR updates JavaScript/Node dependencies, primarily bumping uuid and refreshing the Yarn lockfile to reflect newer transitive package versions.

Changes:

  • Bump uuid from ^8.3.2 to ^14.0.1 in packages/react-native-babel-plugin.
  • Regenerate yarn.lock, resulting in many dependency upgrades/dedupes across Babel and npmcli-related packages.
  • Introduce new transitive dependency entries (e.g., @gar/promise-retry) via updated packages.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
yarn.lock Updates lockfile to newer resolved versions (Babel, npmcli, debug, etc.) and dedupes entries after dependency bump(s).
packages/react-native-babel-plugin/package.json Upgrades uuid major version for the React Native Babel plugin package.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"fast-glob": "^3.3.3",
"svgo": "^4.0.1",
"uuid": "^8.3.2"
"uuid": "^14.0.1"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant