Upgrade react-dom to fix CVE-2018-6341

Summary:
Better safe than sorry even though we're not directly
working with user-supplied data, plugins or apps might.

Reviewed By: danielbuechele

Differential Revision: D14168566

fbshipit-source-id: 8108a2a592d2e2d6b8b2259e0e4bf943cf9c333e
This commit is contained in:
Pascal Hartig
2019-02-21 10:11:15 -08:00
committed by Facebook Github Bot
parent c073aad801
commit 2067e5e1fc
2 changed files with 15 additions and 6 deletions

View File

@@ -95,7 +95,7 @@
"react-color": "^2.11.7",
"react-debounce-render": "^4.0.3",
"react-devtools-core": "3.1.0",
"react-dom": "16",
"react-dom": "^16.0.1",
"react-emotion": "^9.2.6",
"react-redux": "^5.0.7",
"react-test-renderer": "^16.5.2",

View File

@@ -5840,14 +5840,15 @@ react-devtools-core@3.1.0:
shell-quote "^1.6.1"
ws "^2.0.3"
react-dom@16:
version "16.4.0"
resolved "https://registry.yarnpkg.com/react-dom/-/react-dom-16.4.0.tgz#099f067dd5827ce36a29eaf9a6cdc7cbf6216b1e"
react-dom@^16.0.1:
version "16.8.2"
resolved "https://registry.yarnpkg.com/react-dom/-/react-dom-16.8.2.tgz#7c8a69545dd554d45d66442230ba04a6a0a3c3d3"
integrity sha512-cPGfgFfwi+VCZjk73buu14pYkYBR1b/SRMSYqkLDdhSEHnSwcuYTPu6/Bh6ZphJFIk80XLvbSe2azfcRzNF+Xg==
dependencies:
fbjs "^0.8.16"
loose-envify "^1.1.0"
object-assign "^4.1.1"
prop-types "^15.6.0"
prop-types "^15.6.2"
scheduler "^0.13.2"
react-emotion@^9.2.6:
version "9.2.6"
@@ -6477,6 +6478,14 @@ schedule@^0.5.0:
dependencies:
object-assign "^4.1.1"
scheduler@^0.13.2:
version "0.13.2"
resolved "https://registry.yarnpkg.com/scheduler/-/scheduler-0.13.2.tgz#969eaee2764a51d2e97b20a60963b2546beff8fa"
integrity sha512-qK5P8tHS7vdEMCW5IPyt8v9MJOHqTrOUgPXib7tqm9vh834ibBX5BNhwkplX/0iOzHW5sXyluehYfS9yrkz9+w==
dependencies:
loose-envify "^1.1.0"
object-assign "^4.1.1"
semver-diff@^2.0.0:
version "2.1.0"
resolved "https://registry.yarnpkg.com/semver-diff/-/semver-diff-2.1.0.tgz#4bbb8437c8d37e4b0cf1a68fd726ec6d645d6d36"