Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 6, 2025

This PR contains the following updates:

Package Change Age Confidence
@react-native-community/cli (source) 18.0.0 -> 18.0.1 age confidence

GitHub Vulnerability Alerts

CVE-2025-11953

The Metro Development Server, which is opened by the React Native CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.


Release Notes

react-native-community/cli (@​react-native-community/cli)

v18.0.1

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Oslo, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Nov 6, 2025
@renovate renovate bot requested review from JasonVMo and tido64 as code owners November 6, 2025 22:42
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Nov 6, 2025
@renovate renovate bot force-pushed the renovate/npm-react-native-community-cli-vulnerability branch from b0d86d0 to a087f0e Compare November 10, 2025 13:37
@renovate
Copy link
Contributor Author

renovate bot commented Nov 10, 2025

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@tido64 tido64 enabled auto-merge (squash) November 10, 2025 13:50
@tido64 tido64 merged commit a099f9b into trunk Nov 10, 2025
30 checks passed
@tido64 tido64 deleted the renovate/npm-react-native-community-cli-vulnerability branch November 10, 2025 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants