Repository navigation
chore(deps): bump example app to React Native 0.81.6 to drop image-size - #157
Conversation
metro 0.83.8 (React Native 0.81) no longer depends on image-size, which had no fixed 1.x release. Native changes follow the upgrade helper for 0.79.0 -> 0.81.6.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Description of this change
Upgrades the example app from React Native 0.79.0 to 0.81.6. That moves metro from 0.82.5 to 0.83.8, which no longer depends on
image-size, soimage-size@1.2.1(GHSA-5p2g-fcmc-qvqq, high) leavesexample/yarn.lock.Why an upgrade and not a smaller fix:
^0.82.^2.0.3throughresolutionsbreaks metro 0.82. Itssrc/Assets.jscalls the package as a function and passes file paths, and 2.x supports neither.Native changes follow the React Native upgrade helper for 0.79.0 → 0.81.6:
loadReactNative(this)inMainApplication.ktedgeToEdgeEnabled=falsePodfile.lockTemplate hunks skipped:
extendschange. The old path still ships.App.tsxand new-app-screen.exampleTeststarget, so that hunk doesn't apply.The published library in
package/is unchanged, and so is thefile:../packagelockfile entry.Why is this change being made?
How was this tested? How can the reviewer verify your testing?
Tested in
example/on main and on this branch. Environment: Node 23.11, yarn 4.2.2, Xcode 26.1.1, JBR 21.tsc --noEmit./gradlew :app:assembleDebugpod install+xcodebuild)yarn npm audit --all --recursiveAsset-path check: the example has no image assets, so this adds temporary PNG (1x/2x/3x), JPG, GIF and BMP requires in a scratch copy. The width, height and scales written into both bundles are identical before and after.
The app was not launched on a device or simulator.
After pulling: run
rm -rf node_modules && yarn installinexample/. Upgrading an existingnode_modulesin place leaves the new CLI and metro bin files non-executable, and the Android build then fails withnpx ... exit value 126. On an existing Pods checkout,pod installasks forpod update fast_float --no-repo-update.Related issues
Closes Dependabot alert #476. Vanta: KD-18470.
Checklist
Note
Medium Risk
Large native and toolchain bump (SDK 36, Gradle, CocoaPods) confined to the example app; build/runtime regressions are possible but the core library is unchanged.
Overview
Upgrades the example app only from React Native 0.79.0 to 0.81.6 (React 19.1.4, CLI 20.0.0, Node ≥20), with a full lockfile refresh. The published
package/library is untouched.The main driver is dependency hygiene: Metro moves to 0.83.x, which drops the vulnerable
image-sizetransitive (Dependabot GHSA-5p2g-fcmc-qvqq); forcingimage-size2.x on Metro 0.82 was not viable.Android follows the RN 0.81 template: compile/target SDK 36, Kotlin 2.1.20, Gradle 8.14.3;
MainApplicationnow callsloadReactNative(this)instead of manual SoLoader/new-arch bootstrapping; cleartext HTTP is wired viaandroid:usesCleartextTraffic="${usesCleartextTraffic}"on the main manifest and the separate debug manifest is removed;edgeToEdgeEnabled=falseis added ingradle.properties.iOS
Podfile.lockis regenerated for RN 0.81.6 / Hermes 0.81.6 (new inspector-related pods, updated checksums).Reviewed by Cursor Bugbot for commit 32bd35f. Configure here.