Upgrade react-dom to fix CVE-2018-6341
Summary: Better safe than sorry even though we're not directly working with user-supplied data, plugins or apps might. Reviewed By: danielbuechele Differential Revision: D14168566 fbshipit-source-id: 8108a2a592d2e2d6b8b2259e0e4bf943cf9c333e
This commit is contained in:
committed by
Facebook Github Bot
parent
c073aad801
commit
2067e5e1fc
@@ -95,7 +95,7 @@
|
||||
"react-color": "^2.11.7",
|
||||
"react-debounce-render": "^4.0.3",
|
||||
"react-devtools-core": "3.1.0",
|
||||
"react-dom": "16",
|
||||
"react-dom": "^16.0.1",
|
||||
"react-emotion": "^9.2.6",
|
||||
"react-redux": "^5.0.7",
|
||||
"react-test-renderer": "^16.5.2",
|
||||
|
||||
19
yarn.lock
19
yarn.lock
@@ -5840,14 +5840,15 @@ react-devtools-core@3.1.0:
|
||||
shell-quote "^1.6.1"
|
||||
ws "^2.0.3"
|
||||
|
||||
react-dom@16:
|
||||
version "16.4.0"
|
||||
resolved "https://registry.yarnpkg.com/react-dom/-/react-dom-16.4.0.tgz#099f067dd5827ce36a29eaf9a6cdc7cbf6216b1e"
|
||||
react-dom@^16.0.1:
|
||||
version "16.8.2"
|
||||
resolved "https://registry.yarnpkg.com/react-dom/-/react-dom-16.8.2.tgz#7c8a69545dd554d45d66442230ba04a6a0a3c3d3"
|
||||
integrity sha512-cPGfgFfwi+VCZjk73buu14pYkYBR1b/SRMSYqkLDdhSEHnSwcuYTPu6/Bh6ZphJFIk80XLvbSe2azfcRzNF+Xg==
|
||||
dependencies:
|
||||
fbjs "^0.8.16"
|
||||
loose-envify "^1.1.0"
|
||||
object-assign "^4.1.1"
|
||||
prop-types "^15.6.0"
|
||||
prop-types "^15.6.2"
|
||||
scheduler "^0.13.2"
|
||||
|
||||
react-emotion@^9.2.6:
|
||||
version "9.2.6"
|
||||
@@ -6477,6 +6478,14 @@ schedule@^0.5.0:
|
||||
dependencies:
|
||||
object-assign "^4.1.1"
|
||||
|
||||
scheduler@^0.13.2:
|
||||
version "0.13.2"
|
||||
resolved "https://registry.yarnpkg.com/scheduler/-/scheduler-0.13.2.tgz#969eaee2764a51d2e97b20a60963b2546beff8fa"
|
||||
integrity sha512-qK5P8tHS7vdEMCW5IPyt8v9MJOHqTrOUgPXib7tqm9vh834ibBX5BNhwkplX/0iOzHW5sXyluehYfS9yrkz9+w==
|
||||
dependencies:
|
||||
loose-envify "^1.1.0"
|
||||
object-assign "^4.1.1"
|
||||
|
||||
semver-diff@^2.0.0:
|
||||
version "2.1.0"
|
||||
resolved "https://registry.yarnpkg.com/semver-diff/-/semver-diff-2.1.0.tgz#4bbb8437c8d37e4b0cf1a68fd726ec6d645d6d36"
|
||||
|
||||
Reference in New Issue
Block a user