Skip to content

chore(deps): bump yauzl to ^3.2.1#5855

Open
antonis wants to merge 1 commit intomainfrom
antonis/bump-yauzl
Open

chore(deps): bump yauzl to ^3.2.1#5855
antonis wants to merge 1 commit intomainfrom
antonis/bump-yauzl

Conversation

@antonis
Copy link
Contributor

@antonis antonis commented Mar 20, 2026

Adds a scoped resolution for @appium/support@6.1.1/yauzl to bump from 3.2.0 to 3.2.1, fixing an off-by-one error.

Only @appium/support@6.1.1 was affected (the other consumers use yauzl 3.1.3 which is outside the vulnerable range). Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/453

Fixes Dependabot alert for yauzl off-by-one error (affects 3.2.0 only).

https://github.com/getsentry/sentry-react-native/security/dependabot/453

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions
Copy link
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump yauzl to ^3.2.1 by antonis in #5855
  • chore(deps): update JavaScript SDK to v10.45.0 by github-actions in #5848
  • chore(deps): bump flatted from 3.4.1 to 3.4.2 by dependabot in #5853
  • chore(deps): update Cocoa SDK to v9.8.0 by github-actions in #5847
  • fix(tracing): Guard getNewScreenTimeToDisplay behind enableTimeToInitialDisplay by antonis in #5849
  • chore(deps): bump json from 2.16.0 to 2.17.1.2 in /performance-tests by dependabot in #5844
  • chore(docs): Add changelog entry for duplicated breadcrumbs fix by antonis in #5851
  • fix(tracing): Unsubscribe spanEnd listeners after they fire to prevent accumulation by antonis in #5840
  • fix(android): Properly remove duplicated breadcrumbs by vovkasm in #5841
  • fix(tracing): Skip native frames and stall tracking for unsampled spans by antonis in #5842

🤖 This preview updates automatically when you update the PR.

@github-actions
Copy link
Contributor

Fails
🚫 Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against 78909ed

@antonis antonis marked this pull request as ready for review March 20, 2026 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant