[Snyk] Upgrade react-native from 0.63.3 to 0.70.0 #752
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade react-native from 0.63.3 to 0.70.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-SHELLQUOTE-1766506
Why? Has a fix available, CVSS 8.1
SNYK-JS-REACTNATIVE-1298632
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1727253
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1309667
Why? Has a fix available, CVSS 8.1
SNYK-JS-WS-1296835
Why? Has a fix available, CVSS 8.1
SNYK-JS-SIMPLEPLIST-2413671
Why? Has a fix available, CVSS 8.1
SNYK-JS-NODEFETCH-674311
Why? Has a fix available, CVSS 8.1
SNYK-JS-NODEFETCH-2342118
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-629748
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-629268
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-608850
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-2342071
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1015406
Why? Has a fix available, CVSS 8.1
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react-native
-
0.70.0 - 2022-09-05
-
0.70.0-rc.4 - 2022-08-22
- Upgrade RN CLI to v9.0.0, Metro to 0.72.1 (0c2fe96998 by @ thymikee)
- Bump react-native-codegen to 0.70.4 (a22ceecc84 by @ dmitryrykun)
- Hermes version bump for 0.70.0-RC4 (0b4b7774e2 by @ dmitryrykun)
- Update template to gitignore
- Codegen should ignore
-
-
-
-
0.70.0-rc.3 - 2022-08-15
- Bump CLI to latest v9-alpha11 (7e580b97bf by @ kelset)
- Update the new app template to use CMake instead of Android.mk (dfd7f70eff by @ cortinico)
- Refactored usage of kotlin plugin (be35c6dafb by @ hurali97)
- Bump Gradle to 7.5.1 (7a911e0730 by @ AlexanderEggers)
- Upgrade react-native-gradle-plugin to 0.70.2 (1518f838b7 by @ dmitryrykun)
- Silence warning due to react-native internal details. (a4599225f5 by @ cipolleschi)
- Avoid full copy of large folly::dynamic objects in JSIExecutor#defaultTimeoutInvoker (521011d4cc by @ christophpurrer)
- Fix error of release builds with Hermes enabled for Windows users (7fcdb9d9d8 by @ JoseLion)
-
-
-
-
0.70.0-rc.2 - 2022-08-04
-
-
-
- generate a new app (as per command above)
- turn on the new architecture:
- iOS
- Android
- go into
- switch the flag newArchEnabled to
- verify that the app is running new arch by checking the Metro log for something along the lines of
- add a library that has the new TM implementation (such as https://github.com/th3rdwave/react-native-safe-area-context) via
- rerun the app again (remember to do a new
- check in the file
- let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
-
0.70.0-rc.1 - 2022-07-28
-
0.70.0-rc.0 - 2022-07-15
-
0.69.5 - 2022-08-25
- Bump react-native-codegen to 0.69.2 (df3d52bfbf by @ dmitryrykun)
- Replaced reactnativeutilsjni with reactnativejni in the build process to reduce size (54a4fcbfdc by @ SparshaSaha)
- Codegen should ignore
-
0.69.4 - 2022-08-08
- Upgrade RN CLI to v8.0.4 (66c68c37ce by @ thymikee)
- Modified getDefaultJSExecutorFactory method (87cfd386cb by @ KunalFarmah98)
-
0.69.3 - 2022-07-25
-
0.69.2 - 2022-07-20
-
0.69.1 - 2022-06-29
-
0.69.0 - 2022-06-22
-
0.69.0-rc.6 - 2022-06-01
-
0.69.0-rc.5 - 2022-05-31
-
0.69.0-rc.4 - 2022-05-31
-
0.69.0-rc.3 - 2022-05-24
-
0.69.0-rc.2 - 2022-05-20
-
0.69.0-rc.1 - 2022-05-11
-
0.69.0-rc.0 - 2022-04-28
-
0.68.3 - 2022-08-08
- Let's not build reactnativeutilsjni shared library (af9225ec5f by @ SparshaSaha)
- Modified getDefaultJSExecutorFactory method (87cfd386cb by @ KunalFarmah98)
- Use monotonic clock for performance.now() (114d31feee)
- Logging a soft error when ReactRootView has an id other than -1 instead of crashing the app in hybrid apps (1ca2c24930 by @ Kunal-Airtel2022)
-
0.68.2 - 2022-05-09
-
0.68.1 - 2022-04-13
-
0.68.0 - 2022-03-30
-
0.68.0-rc.4 - 2022-03-25
-
0.68.0-rc.3 - 2022-03-17
-
0.68.0-rc.2 - 2022-02-24
-
0.68.0-rc.1 - 2022-02-03
-
0.68.0-rc.0 - 2022-01-28
-
0.67.4 - 2022-03-18
-
0.67.3 - 2022-02-22
-
0.67.2 - 2022-01-31
-
0.67.1 - 2022-01-20
-
0.67.0 - 2022-01-18
-
0.67.0-rc.6 - 2021-12-14
-
0.67.0-rc.5 - 2021-12-06
-
0.67.0-rc.4 - 2021-11-30
-
0.67.0-rc.3 - 2021-11-05
-
0.67.0-rc.2 - 2021-10-25
-
0.67.0-rc.1 - 2021-10-22
-
0.67.0-rc.0 - 2021-10-16
-
0.66.4 - 2021-12-09
-
0.66.3 - 2021-11-10
-
0.66.2 - 2021-11-04
-
0.66.1 - 2021-10-15
-
0.66.0 - 2021-10-01
-
0.66.0-rc.4 - 2021-09-24
-
0.66.0-rc.3 - 2021-09-17
-
0.66.0-rc.2 - 2021-09-10
-
0.66.0-rc.1 - 2021-09-01
-
0.66.0-rc.0 - 2021-08-27
-
0.65.2 - 2021-11-04
-
0.65.1 - 2021-08-19
-
0.65.0 - 2021-08-17
-
0.65.0-rc.4 - 2021-08-11
-
0.65.0-rc.3 - 2021-07-23
-
0.65.0-rc.2 - 2021-06-18
-
0.65.0-rc.1 - 2021-06-17
-
0.65.0-rc.0 - 2021-06-09
-
0.64.3 - 2021-11-04
-
0.64.2 - 2021-06-03
-
0.64.1 - 2021-05-05
-
0.64.0 - 2021-03-12
-
0.64.0-rc.4 - 2021-03-01
-
0.64.0-rc.3 - 2021-02-05
-
0.64.0-rc.2 - 2020-12-18
-
0.64.0-rc.1 - 2020-11-25
-
0.64.0-rc.0 - 2020-11-23
-
0.63.4 - 2020-11-30
-
0.63.3 - 2020-09-29
from react-native GitHub release notes0.70 stable is out!
This release includes 493 commits with 88 contributors! Thank you to all our contributors new and old! See the highlights of the release in our release blog post.
You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Changed
Android specific
android/app/.cxx(542d43df9d by @ leotm)Fixed
.d.tsfiles (0f0d52067c by @ tido64)You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Help us testing 🧪
RC4 is going to be the last RC before 0.70.0 - unless blocking issues arise. To help us catch them, test it by running:
And play around with the fresh app - let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one!
Changed
Android specific
iOS specific
Fixed
Android specific
You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Help us testing 🧪
To test it, run:
And play around with the fresh app - let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one!
To try it, run:
npx react-native init RN070RC2 --version 0.70.0-rc.2You can participate in the conversation on the status of this release in the working group
To help you upgrade to this version, you can use the upgrade helper ⚛️
The full list of changes in release can read in the changelog PR
Help us testing 🧪
We need your help testing one feature in particular with this RC (autolinking of TurboModules from libraries)! Here is what you have to do:
cd iosbundle install && RCT_NEW_ARCH_ENABLED=1 bundle exec pod install(orRCT_NEW_ARCH_ENABLED=1 pod install)cd ..yarn iosgradle.propertiestrueyarn androidLOG Running "RN070RC1" with {"fabric":true,"initialProps":{"concurrentRoot":true},"rootTag":1}yarn add <lib>RCT_NEW_ARCH_ENABLED=1 pod installfor iOS), verify that the lib added works correctlyandroid/app/build/generated/rncli/src/main/jni/Android-rncli.mkthat there's a reference to the library added, something along the lines ofinclude <path>/node_modules/react-native-safe-area-context/android/build/generated/source/codegen/jni/Android.mkimport-codegen-modules :=
libreact_codegen_safeareacontext
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one - or use a different library that is already leveraging the new architecture!
To test it, run:
npx react-native init RN070RC1 --version 0.70.0-rc.1You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Changed
Android specific
Fixed
.d.tsfiles (0f0d52067c by @ tido64)You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file
Changed
Android specific
You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Changed
Android specific
Fixed
Android specific
You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Commit messages
Package name: react-native
.d.tsfiles facebook/react-native#34439)android/app/.cxxfacebook/react-native#34430)helloworld_appmodulesfacebook/react-native#34417).exeto hermesc binary path for Windows users facebook/react-native#34151)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:

🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs