Skip to content

fix(deps): vuln svgo (patch → 4.0.2) [packages/react-native-babel-plugin] - #1358

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/react-native-babel-plugin/3-1785769460
Open

fix(deps): vuln svgo (patch → 4.0.2) [packages/react-native-babel-plugin]#1358
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/react-native-babel-plugin/3-1785769460

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (patch changes only)

Manifests changed:

  • packages/react-native-babel-plugin (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
svgo 4.0.1 4.0.2 patch Direct 1 HIGH

Security Details

🚨 Critical & High Severity (1 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
svgo GHSA-2p49-hgcm-8545 HIGH SVGO removeScripts plugin leaves some executable scripts intact 4.0.1 2.8.3 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

This PR updates the svgo dependency used by the React Native Babel plugin and refreshes the Yarn lockfile to reflect the new resolution (and associated transitive dependency updates).

Changes:

  • Bump svgo from ^4.0.1 to ^4.0.2 in packages/react-native-babel-plugin.
  • Regenerate yarn.lock, pulling in multiple transitive updates (notably Babel/tooling and some npmcli packages).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
yarn.lock Updates resolved versions/checksums for svgo and many transitive dependencies after reinstall/update.
packages/react-native-babel-plugin/package.json Bumps svgo dependency to ^4.0.2.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant