Skip to content

[Snyk] Upgrade react-native from 0.75.4 to 0.86.2 - #130

Open
snyk-io[bot] wants to merge 1 commit into
mainfrom
snyk-upgrade-8b8d73e14a38bbab425a6b57a09c63e1
Open

[Snyk] Upgrade react-native from 0.75.4 to 0.86.2#130
snyk-io[bot] wants to merge 1 commit into
mainfrom
snyk-upgrade-8b8d73e14a38bbab425a6b57a09c63e1

Conversation

@snyk-io

@snyk-io snyk-io Bot commented Aug 27, 2026

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to upgrade react-native from 0.75.4 to 0.86.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 723 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Inefficient Algorithmic Complexity
SNYK-JS-MINIMATCH-15353389
49 Proof of Concept
high severity Infinite loop
SNYK-JS-BRACEEXPANSION-15789759
49 No Known Exploit
high severity Infinite loop
SNYK-JS-NODEFORGE-15789769
49 Proof of Concept
high severity XML Entity Expansion
SNYK-JS-FASTXMLPARSER-15307668
49 Proof of Concept
high severity Inefficient Algorithmic Complexity
SNYK-JS-MINIMATCH-15353389
49 Proof of Concept
high severity XML Entity Expansion
SNYK-JS-FASTXMLPARSER-15677840
49 Proof of Concept
high severity Directory Traversal
SNYK-JS-TAR-15307072
49 Proof of Concept
high severity Infinite loop
SNYK-JS-BRACEEXPANSION-15789759
49 No Known Exploit
high severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-15789773
49 Proof of Concept
high severity Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-15789767
49 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15309438
49 Proof of Concept
high severity Infinite loop
SNYK-JS-IMAGESIZE-9634164
49 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15309438
49 Proof of Concept
high severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-18593780
49 No Known Exploit
high severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-18593780
49 No Known Exploit
high severity Incorrect Regular Expression
SNYK-JS-FASTXMLPARSER-15324289
49 Proof of Concept
high severity Infinite loop
SNYK-JS-IMAGESIZE-17295816
49 Proof of Concept
medium severity Buffer Overflow
SNYK-JS-FASTXMLPARSER-15353391
49 No Known Exploit
medium severity Improper Handling of Unexpected Data Type
SNYK-JS-ONHEADERS-10773729
49 No Known Exploit
critical severity Improper Certificate Validation
SNYK-JS-NODEFORGE-15789771
49 Proof of Concept
high severity Improper Validation of Specified Quantity in Input
SNYK-JS-FASTXMLPARSER-15699647
49 Proof of Concept
high severity Command Injection
SNYK-JS-GLOB-14040952
49 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
49 Proof of Concept
high severity Infinite loop
SNYK-JS-IMAGESIZE-17295814
49 Proof of Concept
high severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-17900054
49 Proof of Concept
high severity Uncontrolled Recursion
SNYK-JS-NODEFORGE-14125745
49 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15353387
49 Proof of Concept
high severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-17900054
49 Proof of Concept
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-TAR-17909152
49 Proof of Concept
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18512280
49 Proof of Concept
high severity Infinite loop
SNYK-JS-TAR-17909068
49 Proof of Concept
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18313044
49 Proof of Concept
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18512280
49 Proof of Concept
high severity Symlink Attack
SNYK-JS-TAR-15456201
49 Proof of Concept
high severity Inefficient Algorithmic Complexity
SNYK-JS-BRACEEXPANSION-17706650
49 No Known Exploit
high severity Inefficient Algorithmic Complexity
SNYK-JS-BRACEEXPANSION-17706650
49 No Known Exploit
high severity Symlink Attack
SNYK-JS-TAR-15416075
49 No Known Exploit
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18313044
49 Proof of Concept
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
49 Proof of Concept
medium severity Uncontrolled Recursion
SNYK-JS-YAML-15765520
49 Proof of Concept
medium severity Directory Traversal
SNYK-JS-TAR-15127355
49 No Known Exploit
medium severity Uncontrolled Recursion
SNYK-JS-TAR-18319500
49 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSYAML-13961110
49 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-JSYAML-13961110
49 No Known Exploit
medium severity Directory Traversal
SNYK-JS-TAR-15032660
49 Proof of Concept
medium severity Improper Handling of Unicode Encoding
SNYK-JS-TAR-15038581
49 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELHELPERS-9397697
49 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-IPADDRESS-16636412
49 No Known Exploit
medium severity Integer Overflow or Wraparound
SNYK-JS-NODEFORGE-14125097
49 No Known Exploit
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-IPADDRESS-18516623
49 Proof of Concept
medium severity Incorrect Type Conversion or Cast
SNYK-JS-TAR-17909104
49 Proof of Concept
medium severity Uncaught Exception
SNYK-JS-TAR-17909225
49 Proof of Concept
medium severity Uncaught Exception
SNYK-JS-JOI-17317897
49 No Known Exploit
medium severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-17342520
49 Proof of Concept
medium severity Interpretation Conflict
SNYK-JS-TAR-17342362
49 Proof of Concept
medium severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-17342520
49 Proof of Concept
low severity Directory Traversal
SNYK-JS-BABELCORE-17342497
49 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
49 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
49 Proof of Concept
critical severity Interpretation Conflict
SNYK-JS-NODEFORGE-14114940
49 No Known Exploit

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade react-native from 0.75.4 to 0.86.2.

See this package in yarn:
react-native

See this project in Snyk:
https://app.snyk.io/org/test-cAX4cfyGGwqSqgMRHFEhFe/project/765ec736-6bd0-471a-a552-bdd8c189c452?utm_source=github-cloud-app&utm_medium=referral&page=upgrade-pr
@snyk-io

snyk-io Bot commented Aug 27, 2026

Copy link
Copy Markdown
Author

Merge Risk: High

Upgrading from React Native 0.75.4 to 0.86.2 is a major undertaking with significant breaking changes. This is not a simple version bump and will require substantial migration effort, including native project modifications and extensive testing.

Key Breaking Changes & Considerations:

  • The New Architecture (Fabric & TurboModules): This upgrade range crosses the complete transition from the legacy architecture to the New Architecture. Version 0.82 was the first to run entirely on it, removing legacy code paths. [2] This is a fundamental shift that can affect performance, rendering, and how native modules are integrated.

  • JavaScript API Changes: Starting in version 0.80, deep imports from the react-native package (e.g., import/require('react-native/Libraries/...')) are deprecated and will cause warnings. [2] Code must be refactored to use public, top-level imports.

  • Toolchain & Environment Requirements: The upgrade will require updating your entire development and build environment. For example, version 0.87 (just beyond the target version) requires Node.js 22, Android Gradle Plugin (AGP) 9, and Kotlin 2.0+. [9] You will need to carefully update your Android and iOS native project files to match the new requirements.

  • Hermes V1 Engine: Version 0.84 made the Hermes V1 JavaScript engine the default, which may introduce subtle behavioral changes. [2]

Recommendation:

This upgrade should be treated as a major project. Do not attempt to apply it directly. Use the official React Native Upgrade Helper web tool to generate a detailed diff of all the changes between 0.75.4 and 0.86.2. [1, 4, 6] This tool is essential for seeing the required changes to your package.json, native configuration files (for both Android and iOS), and other project templates.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@snyk-io
snyk-io Bot requested a review from a team as a code owner August 27, 2026 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants