Skip to content

Commit ec9e173

Browse files
authored
Merge pull request #915 from reactjs/upgrade-react-vulnerability-fix
Upgrade pre-bundled React to v16.4.2 (Vulnerability fix)
2 parents bb3a019 + 6e926f4 commit ec9e173

File tree

8 files changed

+257
-246
lines changed

8 files changed

+257
-246
lines changed

CHANGELOG.md

+6
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,12 @@
88

99
#### Bug Fixes
1010

11+
## 2.4.7
12+
13+
#### New Features
14+
15+
- React 16.4.2 prebundled #914
16+
1117
## 2.4.6
1218

1319
#### New Features

VERSIONS.md

+2-1
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@ You can control what version of React.js (and JSXTransformer) is used by `react-
99

1010
| Gem | React.js |
1111
|----------|----------|
12-
| master | 16.4.1 |
12+
| master | 16.4.2 |
13+
| 2.4.7 | 16.4.2 |
1314
| 2.4.6 | 16.4.1 |
1415
| 2.4.5 | 16.3.2 |
1516
| 2.4.4 | 16.2.0 |

lib/assets/react-source/development/react-server.js

+40-37
Large diffs are not rendered by default.

lib/assets/react-source/development/react.js

+190-189
Large diffs are not rendered by default.

lib/assets/react-source/production/react-server.js

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

lib/assets/react-source/production/react.js

+5-5
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

lib/react/rails/version.rb

+1-1
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,6 @@ module React
22
module Rails
33
# If you change this, make sure to update VERSIONS.md
44
# and republish the UJS by updating package.json and `bundle exec rake ujs:publish`
5-
VERSION = '2.4.6'
5+
VERSION = '2.4.7'
66
end
77
end

react-builds/yarn.lock

+10-10
Original file line numberDiff line numberDiff line change
@@ -155,8 +155,8 @@ center-align@^0.1.1:
155155
lazy-cache "^1.0.3"
156156

157157
chain-function@^1.0.0:
158-
version "1.0.0"
159-
resolved "https://registry.yarnpkg.com/chain-function/-/chain-function-1.0.0.tgz#0d4ab37e7e18ead0bdc47b920764118ce58733dc"
158+
version "1.0.1"
159+
resolved "https://registry.yarnpkg.com/chain-function/-/chain-function-1.0.1.tgz#c63045e5b4b663fb86f1c6e186adaf1de402a1cc"
160160

161161
chokidar@^1.0.0:
162162
version "1.7.0"
@@ -755,8 +755,8 @@ npm-bundled@^1.0.1:
755755
resolved "https://registry.yarnpkg.com/npm-bundled/-/npm-bundled-1.0.3.tgz#7e71703d973af3370a9591bafe3a63aca0be2308"
756756

757757
npm-packlist@^1.1.6:
758-
version "1.1.10"
759-
resolved "https://registry.yarnpkg.com/npm-packlist/-/npm-packlist-1.1.10.tgz#1039db9e985727e464df066f4cf0ab6ef85c398a"
758+
version "1.1.11"
759+
resolved "https://registry.yarnpkg.com/npm-packlist/-/npm-packlist-1.1.11.tgz#84e8c683cbe7867d34b1d357d893ce29e28a02de"
760760
dependencies:
761761
ignore-walk "^3.0.1"
762762
npm-bundled "^1.0.1"
@@ -905,8 +905,8 @@ rc@^1.2.7:
905905
strip-json-comments "~2.0.1"
906906

907907
react-dom@^16.4.1:
908-
version "16.4.1"
909-
resolved "https://registry.yarnpkg.com/react-dom/-/react-dom-16.4.1.tgz#7f8b0223b3a5fbe205116c56deb85de32685dad6"
908+
version "16.4.2"
909+
resolved "https://registry.yarnpkg.com/react-dom/-/react-dom-16.4.2.tgz#4afed569689f2c561d2b8da0b819669c38a0bda4"
910910
dependencies:
911911
fbjs "^0.8.16"
912912
loose-envify "^1.1.0"
@@ -922,8 +922,8 @@ [email protected]:
922922
warning "^3.0.0"
923923

924924
react@^16.4.1:
925-
version "16.4.1"
926-
resolved "https://registry.yarnpkg.com/react/-/react-16.4.1.tgz#de51ba5764b5dbcd1f9079037b862bd26b82fe32"
925+
version "16.4.2"
926+
resolved "https://registry.yarnpkg.com/react/-/react-16.4.2.tgz#2cd90154e3a9d9dd8da2991149fdca3c260e129f"
927927
dependencies:
928928
fbjs "^0.8.16"
929929
loose-envify "^1.1.0"
@@ -1104,8 +1104,8 @@ tapable@^0.1.8, tapable@~0.1.8:
11041104
resolved "https://registry.yarnpkg.com/tapable/-/tapable-0.1.10.tgz#29c35707c2b70e50d07482b5d202e8ed446dafd4"
11051105

11061106
tar@^4:
1107-
version "4.4.4"
1108-
resolved "https://registry.yarnpkg.com/tar/-/tar-4.4.4.tgz#ec8409fae9f665a4355cc3b4087d0820232bb8cd"
1107+
version "4.4.6"
1108+
resolved "https://registry.yarnpkg.com/tar/-/tar-4.4.6.tgz#63110f09c00b4e60ac8bcfe1bf3c8660235fbc9b"
11091109
dependencies:
11101110
chownr "^1.0.1"
11111111
fs-minipass "^1.2.5"

0 commit comments

Comments
 (0)