Skip to content

fix(deps): vuln svgo (patch → 4.0.2) [packages/react-native-babel-plugin] - #1374

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/react-native-babel-plugin/2-1786950240
Open

fix(deps): vuln svgo (patch → 4.0.2) [packages/react-native-babel-plugin]#1374
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/react-native-babel-plugin/2-1786950240

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (patch changes only)

Manifests changed:

  • packages/react-native-babel-plugin (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
svgo 4.0.1 4.0.2 patch Direct 2 HIGH

Security Details

🚨 Critical & High Severity (2 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
svgo GHSA-2p49-hgcm-8545 HIGH SVGO removeScripts plugin leaves some executable scripts intact 4.0.1 2.8.3 -
svgo CVE-2026-73650 HIGH SVGO: removeScripts plugin leaves some executable scripts intact 4.0.1 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates the svgo dependency to the latest patch release and refreshes the Yarn lockfile to reflect resolved dependency versions.

Changes:

  • Bumped svgo from ^4.0.1 to ^4.0.2 in packages/react-native-babel-plugin.
  • Updated yarn.lock, including svgo resolution and a large set of transitive dependency re-resolves/upgrades.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
yarn.lock Reflects updated resolutions after dependency bump; includes many additional transitive updates.
packages/react-native-babel-plugin/package.json Bumps svgo dependency from ^4.0.1 to ^4.0.2.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@sbarrio
sbarrio requested a review from cdn34dd August 18, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant