Skip to content

chore(deps): bump yauzl to ^3.2.1#5855

Merged
antonis merged 4 commits intomainfrom
antonis/bump-yauzl
Mar 23, 2026
Merged

chore(deps): bump yauzl to ^3.2.1#5855
antonis merged 4 commits intomainfrom
antonis/bump-yauzl

Conversation

@antonis
Copy link
Contributor

@antonis antonis commented Mar 20, 2026

Adds a scoped resolution for @appium/support@6.1.1/yauzl to bump from 3.2.0 to 3.2.1, fixing an off-by-one error.

Only @appium/support@6.1.1 was affected (the other consumers use yauzl 3.1.3 which is outside the vulnerable range). Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/453

Fixes Dependabot alert for yauzl off-by-one error (affects 3.2.0 only).

https://github.com/getsentry/sentry-react-native/security/dependabot/453

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions
Copy link
Contributor

github-actions bot commented Mar 20, 2026

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump yauzl to ^3.2.1 by antonis in #5855
  • chore(deps): bump appium from 2.4.1 to 3.2.2 by antonis in #5856
  • fix(ios): Guard replay postInit behind runtime session replay check by antonis in #5858
  • Add better needs_web check to CI by alwx in #5863
  • chore(deps): bump fast-xml-parser to ^5.5.7 by antonis in #5854
  • CI: detect-changes workflow to only check the affected components on the CI side by alwx in #5843
  • chore(deps): bump getsentry/craft/.github/workflows/changelog-preview.yml from 2.24.1 to 2.25.0 by dependabot in #5861
  • chore(deps): bump getsentry/craft from 2.24.1 to 2.25.0 by dependabot in #5862
  • chore(deps): bump github/codeql-action from 4.32.6 to 4.34.1 by dependabot in #5860
  • chore(deps): update JavaScript SDK to v10.45.0 by github-actions in #5848
  • chore(deps): bump flatted from 3.4.1 to 3.4.2 by dependabot in #5853
  • chore(deps): update Cocoa SDK to v9.8.0 by github-actions in #5847
  • fix(tracing): Guard getNewScreenTimeToDisplay behind enableTimeToInitialDisplay by antonis in #5849
  • chore(deps): bump json from 2.16.0 to 2.17.1.2 in /performance-tests by dependabot in #5844
  • chore(docs): Add changelog entry for duplicated breadcrumbs fix by antonis in #5851
  • fix(tracing): Unsubscribe spanEnd listeners after they fire to prevent accumulation by antonis in #5840
  • fix(android): Properly remove duplicated breadcrumbs by vovkasm in #5841
  • fix(tracing): Skip native frames and stall tracking for unsampled spans by antonis in #5842

🤖 This preview updates automatically when you update the PR.

@antonis antonis marked this pull request as ready for review March 20, 2026 12:01
Copy link
Collaborator

@lucas-zimerman lucas-zimerman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! After ready to merge test pass

@lucas-zimerman lucas-zimerman added the ready-to-merge Triggers the full CI test suite label Mar 23, 2026
antonis and others added 3 commits March 23, 2026 13:23
Resolve yarn.lock conflict by reinstalling.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis antonis enabled auto-merge (squash) March 23, 2026 13:18
@antonis antonis merged commit d7c03d0 into main Mar 23, 2026
54 of 79 checks passed
@antonis antonis deleted the antonis/bump-yauzl branch March 23, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-merge Triggers the full CI test suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants