Skip to content

[Snyk] Upgrade react-scripts from 4.0.0 to 4.0.3#280

Open
dingo4dev wants to merge 1 commit intomainfrom
snyk-upgrade-b198cee7be9eecb4a6ef6d3349c507c2
Open

[Snyk] Upgrade react-scripts from 4.0.0 to 4.0.3#280
dingo4dev wants to merge 1 commit intomainfrom
snyk-upgrade-b198cee7be9eecb4a6ef6d3349c507c2

Conversation

@dingo4dev
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade react-scripts from 4.0.0 to 4.0.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.

  • The recommended version was released 4 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Remote Memory Exposure
SNYK-JS-DNSPACKET-1293563
387 No Known Exploit
high severity Prototype Pollution
SNYK-JS-ASYNC-2441827
387 Proof of Concept
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
387 No Known Exploit
high severity Improper Input Validation
SNYK-JS-URLPARSE-2407770
387 Proof of Concept
high severity Prototype Pollution
SNYK-JS-IMMER-1019369
387 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
387 Proof of Concept
medium severity Command Injection
SNYK-JS-REACTDEVUTILS-1083268
387 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
387 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-BOOTSTRAP-7444580
387 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-BOOTSTRAP-7444593
387 Proof of Concept
medium severity Authorization Bypass Through User-Controlled Key
SNYK-JS-URLPARSE-2412697
387 Proof of Concept
medium severity Information Exposure
SNYK-JS-EVENTSOURCE-2823375
387 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
387 No Known Exploit
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
387 No Known Exploit
medium severity Improper Handling of Unexpected Data Type
SNYK-JS-ONHEADERS-10773729
387 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
387 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-8482416
387 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-URLPARSE-1078283
387 No Known Exploit
medium severity Open Redirect
SNYK-JS-URLPARSE-1533425
387 Proof of Concept
medium severity Access Restriction Bypass
SNYK-JS-URLPARSE-2401205
387 Proof of Concept
medium severity Authorization Bypass
SNYK-JS-URLPARSE-2407759
387 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
387 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
387 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
387 No Known Exploit
Release notes
Package name: react-scripts
  • 4.0.3 - 2021-02-22
  • 4.0.2 - 2021-02-03
  • 4.0.1 - 2020-11-23
  • 4.0.0 - 2020-10-23
from react-scripts GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade react-scripts from 4.0.0 to 4.0.3.

See this package in npm:
react-scripts

See this project in Snyk:
https://app.snyk.io/org/stanleyl4/project/f88e03e9-0a3b-432e-b04f-287f49abf148?utm_source=github&utm_medium=referral&page=upgrade-pr
Copilot AI review requested due to automatic review settings August 11, 2025 08:05
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR upgrades the react-scripts dependency from version 4.0.0 to 4.0.3 to address multiple security vulnerabilities identified by Snyk. The upgrade resolves 24 security issues ranging from high-severity vulnerabilities like Remote Memory Exposure and Prototype Pollution to medium and low-severity issues including Cross-site Scripting (XSS) and Regular Expression Denial of Service (ReDoS).

  • Upgrades react-scripts from 4.0.0 to 4.0.3 (3 patch versions ahead)
  • Resolves 24 identified security vulnerabilities across various severity levels
  • Maintains compatibility within the same major version to minimize breaking changes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants