-
Notifications
You must be signed in to change notification settings - Fork 24
[Snyk] Upgrade @react-native/metro-config from 0.75.2 to 0.80.1 #122
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
[Snyk] Upgrade @react-native/metro-config from 0.75.2 to 0.80.1 #122
Conversation
Snyk has created this PR to upgrade @react-native/metro-config from 0.75.2 to 0.80.1. See this package in yarn: @react-native/metro-config See this project in Snyk: https://app.snyk.io/org/shamoilattaar-wednesday/project/23dc2955-1a0d-48a4-af49-06d3e4b79f8f?utm_source=github&utm_medium=referral&page=upgrade-pr
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the ✨ Finishing Touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Summary of Changes
Hello @shamoilattaar-wednesday, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!
This pull request is an automated dependency upgrade, primarily targeting @react-native/metro-config to version 0.80.1. The main objective is to ensure the project's dependencies are up-to-date, which is crucial for security, stability, and long-term maintainability. This update has led to a comprehensive refresh of many underlying transitive dependencies, particularly within the JavaScript build toolchain.
Highlights
- Core Dependency Upgrade: Upgraded the primary dependency
@react-native/metro-configfrom version0.75.2to0.80.1. This update was automatically initiated by Snyk to keep project dependencies current. - Extensive Transitive Dependency Updates: This core dependency upgrade triggered a significant cascade of updates across numerous related packages. This includes a wide range of
@babelpackages (e.g.,@babel/core,@babel/parser,@babel/runtime, and various helper and plugin packages) and manymetro-*packages (e.g.,metro-config,metro-babel-transformer,metro-runtime). - React Native Ecosystem Updates: Several other
@react-native/*dependencies, such as@react-native/babel-plugin-codegen,@react-native/babel-preset,@react-native/codegen, and@react-native/js-polyfills, were also updated to align with the new0.80.xversion series. Additionally,@react-native-async-storage/async-storagesaw an update from^2.0.0to1.23.1.
Using Gemini Code Assist
The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.
Invoking Gemini
You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.
| Feature | Command | Description |
|---|---|---|
| Code Review | /gemini review |
Performs a code review for the current pull request in its current state. |
| Pull Request Summary | /gemini summary |
Provides a summary of the current pull request in its current state. |
| Comment | @gemini-code-assist | Responds in comments when explicitly tagged, both in issue comments and review comments. |
| Help | /gemini help |
Displays a list of available commands. |
Customization
To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.
Limitations & Feedback
Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments or fill out our survey to provide feedback.
You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.
Footnotes
-
Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request upgrades @react-native/metro-config from a pre-release version. It's crucial to evaluate this upgrade carefully due to potential risks:
- Upgrading a core tooling package in isolation within an Expo project can lead to version mismatches and build breaks. It's better to upgrade the
expopackage itself. - The update causes a major version downgrade for
@react-native-async-storage/async-storage, a potentially breaking change. - The
@react-native/codegenpackage has undergone significant internal changes, which could affect the project's code generation process.
Consider an expo upgrade instead to ensure dependency compatibility.
| "@react-native-async-storage/async-storage": "1.23.1", | ||
| "@react-native-community/masked-view": "^0.1.11", | ||
| "@react-native/metro-config": "^0.75.0-main", | ||
| "@react-native/metro-config": "^0.80.1", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Upgrading @react-native/metro-config from a pre-release version (^0.75.0-main) to ^0.80.1 is a significant change, especially within an Expo project. This upgrade pulls in a new major version of metro-config which may introduce breaking changes to the build process.
In an Expo-managed project, it is highly recommended to manage toolchain versions by upgrading the expo package itself, rather than individual packages like this. This ensures all related dependencies are kept at compatible versions, preventing potential build failures or runtime errors.
| "@react-native-async-storage/async-storage@1.23.1": | ||
| version "1.23.1" | ||
| resolved "https://registry.yarnpkg.com/@react-native-async-storage/async-storage/-/async-storage-1.23.1.tgz#cad3cd4fab7dacfe9838dce6ecb352f79150c883" | ||
| integrity sha512-Qd2kQ3yi6Y3+AcUlrHxSLlnBvpdCEMVGFlVBneVOjaFaPU61g1huc38g339ysXspwY1QZA2aNhrk/KlHGO+ewA== |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This dependency upgrade appears to have caused a transitive dependency on @react-native-async-storage/async-storage to be downgraded from 2.0.0 to 1.23.1. This is a major version downgrade and is likely to cause runtime errors if any part of the application or its dependencies relied on APIs from v2.0.0.
| "@react-native/codegen@0.80.2": | ||
| version "0.80.2" | ||
| resolved "https://registry.yarnpkg.com/@react-native/codegen/-/codegen-0.80.2.tgz#2e5dc975400d41b84c7393d73cfe32f47b12d82e" | ||
| integrity sha512-eYad9ex9/RS6oFbbpu6LxsczktbhfJbJlTvtRlcWLJjJbFTeNr5Q7CgBT2/m5VtpxnJ/0YdmZ9vdazsJ2yp9kw== | ||
| dependencies: | ||
| "@babel/parser" "^7.20.0" | ||
| glob "^7.1.1" | ||
| hermes-parser "0.22.0" | ||
| hermes-parser "0.28.1" | ||
| invariant "^2.2.4" | ||
| jscodeshift "^0.14.0" | ||
| mkdirp "^0.5.1" | ||
| nullthrows "^1.1.1" | ||
| yargs "^17.6.2" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Coverage reportStatements coverage not met for global: expected >=80%, but got 79.09604519774011%
Test suite run success47 tests passing in 17 suites. Report generated by 🧪jest coverage report action from 3e83053 |
Snyk has created this PR to upgrade @react-native/metro-config from 0.75.2 to 0.80.1.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 354 versions ahead of your current version.
The recommended version was released a month ago.
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: