fix(deps): vuln svgo (patch → 4.0.2) [packages/react-native-babel-plugin] - #1374
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the svgo dependency to the latest patch release and refreshes the Yarn lockfile to reflect resolved dependency versions.
Changes:
- Bumped
svgofrom^4.0.1to^4.0.2inpackages/react-native-babel-plugin. - Updated
yarn.lock, includingsvgoresolution and a large set of transitive dependency re-resolves/upgrades.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| yarn.lock | Reflects updated resolutions after dependency bump; includes many additional transitive updates. |
| packages/react-native-babel-plugin/package.json | Bumps svgo dependency from ^4.0.1 to ^4.0.2. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
PRApprover will approve and merge this PR, FAQ, #dx-source-code-management 🛠️ PRApproval Status
➡️ Current phase: ⏳ Merge via MergeQueue is already in progress... |
Summary: High-severity security update — 1 package upgraded (patch changes only)
Manifests changed:
packages/react-native-babel-plugin(yarn)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Security Details
🚨 Critical & High Severity (2 fixed)
Review Checklist
Standard review:
Update Mode: all_vulns
🤖 Generated by DataDog Automated Dependency Management System