Update dependency @react-native-community/cli to v17 [SECURITY] - autoclosed #1805
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
11.3.7->17.0.1GitHub Vulnerability Alerts
CVE-2025-11953
The Metro Development Server, which is opened by the React Native CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Release Notes
react-native-community/cli (@react-native-community/cli)
v17.0.1Compare Source
v17.0.0Compare Source
What's Changed
sudo-promptwith@vscode/sudo-promptby @szymonrybczak in #2578PodfileandPodfile.lockchanged when deciding to install Cocoapods by @szymonrybczak in #2443RCT_IGNORE_PODS_DEPRECATIONenv variable topod installby @szymonrybczak in #2601createDevServerMiddlewarefromcliby @robhogan in #2605link-assetscli setup guides by @Nova41 in #2572New Contributors
Full Changelog: react-native-community/cli@v16.0.2...v17.0.0
v16.0.3Compare Source
v16.0.2Compare Source
What's Changed
loadConfig()failing with "missing loader for extension" by @tido64 in #2549loadConfig()failing with "missing loader for extension" by @tido64 in #2550New Contributors
Full Changelog: react-native-community/cli@v15.1.0...v16.0.2
v16.0.1Compare Source
v16.0.0Compare Source
v15.1.3Compare Source
v15.1.2Compare Source
v15.1.1Compare Source
v15.1.0Compare Source
Changes
loadConfig()failing with "missing loader for extension" @tido64 (#2550)loadConfig()failing with "missing loader for extension" @tido64 (#2549)🚀 Features
createDevServerMiddlewarefromcli@robhogan (#2605)RCT_IGNORE_PODS_DEPRECATIONenv variable topod install@szymonrybczak (#2601)react-native.config@szymonrybczak (#2453)🐛 Bug Fixes
PodfileandPodfile.lockchanged when deciding to install Cocoapods @szymonrybczak (#2443)🧰 Maintenance
12 changes
link-assetscli setup guides @Nova41 (#2572)sudo-promptwith@vscode/sudo-prompt@szymonrybczak (#2578)Full Changelog: react-native-community/cli@v15.0.1...v15.1.0
v15.0.1Compare Source
What's Changed
cli-config-applefor linking by @thymikee in #2536New Contributors
Full Changelog: react-native-community/cli@v15.0.0...v15.0.1
v15.0.0Compare Source
What's Changed
react-native-macostest by @szymonrybczak in #2500promptsby @tido64 in #2518New Contributors
Full Changelog: react-native-community/cli@v14.1.0...v15.0.0
v14.1.2Compare Source
v14.1.1Compare Source
v14.1.0Compare Source
What's Changed
fast-xml-parserfrom 4.2.4 and 4.3.2 to 4.4.1 by @Romick2005 in #2466--deviceoption tobuild-ioscommand by @szymonrybczak in #2482New Contributors
Full Changelog: react-native-community/cli@v14.0.1...v14.1.0
v14.0.1Compare Source
v14.0.0Compare Source
v13.6.9Compare Source
v13.6.8Compare Source
v13.6.7Compare Source
v13.6.6Compare Source
v13.6.5Compare Source
Fixes
Full Changelog: react-native-community/cli@v13.6.4...v13.6.5
v13.6.4Compare Source
v13.6.3Compare Source
v13.6.2Compare Source
v13.6.1Compare Source
This is the collective changelog for v13 of the CLI that's intended for use with React Native 0.74.
Features
nodeLinker: node-modulesfor new projects by @szymonrybczak in #2134buildRunto properly open macOS apps by @szymonrybczak in #2232react-native.config.jsby @szymonrybczak in #2229unstable_reactLegacyComponentNamesby @cortinico in #2264--yarn-config-optionsoption by @szymonrybczak in #2273getSimulators()for OOT platforms by @okwasniewski in #2239Fixes
yarnas package manager when callinginitwithnpxby @szymonrybczak in #2216run-androidon windows. by @aajahid in #2236envinxcodebuildby @szymonrybczak in #2245run-ios/androidwhen failed to start packager by @szymonrybczak in #2252--devicewithout value by @szymonrybczak in #2263ippackage with default value and--hostflag by @szymonrybczak in #2299execaphantom dependency in cli-tools by @jbroma in #2292AUTOLINKED_LIBRARIESby @cortinico in #2306Chore & Maintenance
getXcodeProjectAndDirby @okwasniewski in #2220prompts.tsby @szymonrybczak in #2224getLatestRelease.tsto usecurrentVersionindiffUrlby @kraenhansen in #2231editTemplatetest on Node v20 by @szymonrybczak in #2235cli-plugin-metropackage remnants by @szymonrybczak in #2272update-metro.jsscript by @szymonrybczak in #2281--tasksoption description by @szymonrybczak in #2290New Contributors
Full Changelog: react-native-community/cli@v12.3.6...v13.6.1
v13.6.0Compare Source
v13.5.2Compare Source
v13.5.1Compare Source
v13.5.0Compare Source
v13.4.0Compare Source
v13.3.0Compare Source
v13.2.0Compare Source
v13.1.0: v12.3.0Compare Source
What's Changed
Full Changelog: react-native-community/cli@v13.0.1...v13.1.0
v13.0.1Compare Source
v13.0.0Compare Source
What's Changed
README.mdby @szymonrybczak in #2190Full Changelog: react-native-community/cli@v12.2.0...v13.0.0
v12.3.7Compare Source
v12.3.6Compare Source
What's Changed
ippackage with default value and--hostflag by @szymonrybczak in #2301Full Changelog: react-native-community/cli@v12.3.5...v12.3.6
v12.3.5Compare Source
What's changed
envinxcodebuild(#2245) @szymonrybczakFull Changelog: react-native-community/cli@v12.3.4...v12.3.5
v12.3.4Compare Source
What's Changed
Full Changelog: react-native-community/cli@v12.3.3...v12.3.4
v12.3.3Compare Source
What's Changed
--devicewithout value by @szymonrybczak in #2265Full Changelog: react-native-community/cli@v12.3.2...v12.3.3
v12.3.2Compare Source
What's Changed
Full Changelog: react-native-community/cli@v12.3.1...v12.3.2
v12.3.1Compare Source
Fixes
run-androidon windows. (#2236) @aajahidyarnas package manager when callinginitwithnpx(#2216) @szymonrybczakFull Changelog: react-native-community/cli@v12.3.0...v12.3.1
v12.3.0Compare Source
What's Changed
Full Changelog: react-native-community/cli@v12.2.1...v12.3.0
v12.2.1Compare Source
v12.2.0Compare Source
Changes
🚀 Features
doctorcommand in issue template @szymonrybczak (#2186)--skip-git-initto opt out git init @szymonrybczak (#2177)🐛 Bug Fixes
README.md@szymonrybczak (#2190)AndroidManifest.xml@szymonrybczak (#2187)run-ioscommand @TMisiukiewicz (#2173)🧰 Maintenance
5 changes
initdocs with current state @szymonrybczak (#2178)rootargument @szymonrybczak (#2164)use_native_modules@szymonrybczak (#2185)doctorcommand in issue template @szymonrybczak (#2186)initdocs with current state @szymonrybczak (#2178)native_modules.rbtests @thymikee (#2188)Full Changelog: react-native-community/cli@v12.1.1...v12.2.0
v12.1.1Compare Source
What's Changed
Full Changelog: react-native-community/cli@v12.1.0...v12.1.1
v12.1.0Compare Source
🚀 Features
--platform-nameoption toinitfor out of tree platforms init @okwasniewski (#2170)🐛 Bug Fixes
🧰 Maintenance
runUntilfunction @szymonrybczak (#2147)fs.rmdirwithfs.rm@szymonrybczak (#2160)Full Changelog: react-native-community/cli@v12.0.0...v12.1.0
v12.0.0Compare Source
This version of React Native CLI targets React Native 0.73 and includes numerous bug fixes, features and performance improvements.
Breaking changes
taskPrefixinbuild-androidcommand fromassembletobundleby @szymonrybczak in #1913Configuration
📅 Schedule: Branch creation - "" in timezone Europe/London, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.