Skip to content

chore(deps): bump example app to React Native 0.81.6 to drop image-size - #157

Merged
ethanpschoen merged 1 commit into
mainfrom
ethan/chore/example-image-size-2
Sep 25, 2026
Merged

ethanpschoen merged 1 commit into
mainfrom
ethan/chore/example-image-size-2

Conversation

@ethanpschoen

@ethanpschoen ethanpschoen commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description of this change

Upgrades the example app from React Native 0.79.0 to 0.81.6. That moves metro from 0.82.5 to 0.83.8, which no longer depends on image-size, so image-size@1.2.1 (GHSA-5p2g-fcmc-qvqq, high) leaves example/yarn.lock.

Why an upgrade and not a smaller fix:

  • No metro release depends on image-size 2.x.
  • React Native 0.79 and 0.80 are capped at metro ^0.82.
  • Forcing image-size ^2.0.3 through resolutions breaks metro 0.82. Its src/Assets.js calls the package as a function and passes file paths, and 2.x supports neither.

Native changes follow the React Native upgrade helper for 0.79.0 → 0.81.6:

  • compile/target SDK 36, Kotlin 2.1.20, Gradle 8.14.3
  • loadReactNative(this) in MainApplication.kt
  • cleartext traffic set through the manifest placeholder, replacing the debug manifest
  • edgeToEdgeEnabled=false
  • regenerated Podfile.lock

Template hunks skipped:

  • The Gradle wrapper jar and scripts. The old jar downloads 8.14.3.
  • The tsconfig extends change. The old path still ships.
  • The TypeScript bump. tsc passes on 5.0.4.
  • The template's demo App.tsx and new-app-screen.
  • The pbxproj cleanup. This project has a real exampleTests target, so that hunk doesn't apply.

The published library in package/ is unchanged, and so is the file:../package lockfile entry.

Why is this change being made?

  • Chore (non-functional changes)
  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

How was this tested? How can the reviewer verify your testing?

Tested in example/ on main and on this branch. Environment: Node 23.11, yarn 4.2.2, Xcode 26.1.1, JBR 21.

Check main this branch
tsc --noEmit 0 errors 0 errors
eslint 0 errors, 1 existing warning same
Android / iOS prod bundle pass pass
./gradlew :app:assembleDebug BUILD SUCCESSFUL BUILD SUCCESSFUL
iOS simulator Debug build (pod install + xcodebuild) BUILD SUCCEEDED BUILD SUCCEEDED
yarn npm audit --all --recursive 9 findings, incl. 2 image-size 7 (image-size gone, nothing new)

Asset-path check: the example has no image assets, so this adds temporary PNG (1x/2x/3x), JPG, GIF and BMP requires in a scratch copy. The width, height and scales written into both bundles are identical before and after.

The app was not launched on a device or simulator.

After pulling: run rm -rf node_modules && yarn install in example/. Upgrading an existing node_modules in place leaves the new CLI and metro bin files non-executable, and the Android build then fails with npx ... exit value 126. On an existing Pods checkout, pod install asks for pod update fast_float --no-repo-update.

Related issues

Closes Dependabot alert #476. Vanta: KD-18470.

Checklist

  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • I have evaluated the security impact of this change, and OWASP Secure Coding Practices have been observed.
  • I have informed stakeholders of my changes.

Note

Medium Risk
Large native and toolchain bump (SDK 36, Gradle, CocoaPods) confined to the example app; build/runtime regressions are possible but the core library is unchanged.

Overview
Upgrades the example app only from React Native 0.79.0 to 0.81.6 (React 19.1.4, CLI 20.0.0, Node ≥20), with a full lockfile refresh. The published package/ library is untouched.

The main driver is dependency hygiene: Metro moves to 0.83.x, which drops the vulnerable image-size transitive (Dependabot GHSA-5p2g-fcmc-qvqq); forcing image-size 2.x on Metro 0.82 was not viable.

Android follows the RN 0.81 template: compile/target SDK 36, Kotlin 2.1.20, Gradle 8.14.3; MainApplication now calls loadReactNative(this) instead of manual SoLoader/new-arch bootstrapping; cleartext HTTP is wired via android:usesCleartextTraffic="${usesCleartextTraffic}" on the main manifest and the separate debug manifest is removed; edgeToEdgeEnabled=false is added in gradle.properties.

iOS Podfile.lock is regenerated for RN 0.81.6 / Hermes 0.81.6 (new inspector-related pods, updated checksums).

Reviewed by Cursor Bugbot for commit 32bd35f. Configure here.

metro 0.83.8 (React Native 0.81) no longer depends on image-size, which
had no fixed 1.x release. Native changes follow the upgrade helper for
0.79.0 -> 0.81.6.
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Potential vulnerability: npm @react-native-community/cli with risk level "medium"

Location: Package overview

From: example/package.json → npm/@react-native-community/cli@20.0.0

ℹ Read more on: This package | This alert | Navigating potential vulnerabilities

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: It is advisable to proceed with caution. Engage in a review of the package's security aspects and consider reaching out to the package maintainer for the latest information or patches.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@react-native-community/cli@20.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ethanpschoen
ethanpschoen marked this pull request as ready for review September 25, 2026 19:32
@ethanpschoen
ethanpschoen requested review from a team as code owners September 25, 2026 19:32
@ethanpschoen
ethanpschoen merged commit ea170ac into main Sep 25, 2026
13 checks passed
@ethanpschoen
ethanpschoen deleted the ethan/chore/example-image-size-2 branch September 25, 2026 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants