release: v3.12.9 - #320
release: v3.12.9#320
Conversation
|
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-1525 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-54906 | concurrent-ruby |
1.3.3 |
1.3.7 |
| CVE-2026-45363 | jwt |
2.10.2 |
2.10.3 |
| CVE-2026-45623 | postcss |
8.4.49 |
8.5.12 |
| CVE-2026-33210 | json |
2.16.0 |
2.17.1.2 |
| CVE-2026-33896 | node-forge |
1.3.1 |
1.4.0 |
🔶 High · 48 findings
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-83616 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-41675 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2026-54297 | faraday |
1.10.4 |
1.10.6 |
| CVE-2026-35611 | addressable |
2.8.7 |
2.9.0 |
| CVE-2026-41907 | uuid |
7.0.3 |
11.1.1 |
| CVE-2026-83619 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-83605 | @xmldom/xmldom |
0.7.13 |
0.8.14 |
| CVE-2026-2229 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-83605 | @xmldom/xmldom |
0.8.11 |
0.8.14 |
| CVE-2026-33176 | activesupport |
7.2.3 |
7.2.3.1 |
| CVE-2026-41672 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2025-66031 | node-forge |
1.3.1 |
1.3.2 |
| CVE-2026-22036 | undici |
6.22.0 |
6.23.0 |
| CVE-2026-83607 | @xmldom/xmldom |
0.8.11 |
0.8.14 |
| CVE-2026-83616 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
| CVE-2026-33894 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-54904 | concurrent-ruby |
1.3.3 |
1.3.7 |
| CVE-2026-1528 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-33891 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-34601 | @xmldom/xmldom |
0.8.11 |
0.8.12 |
| CVE-2026-83615 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-1526 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-41907 | uuid |
3.4.0 |
11.1.1 |
| CVE-2026-83607 | @xmldom/xmldom |
0.7.13 |
0.8.14 |
| CVE-2026-73646 | postcss |
8.4.49 |
8.5.18 |
| CVE-2026-83613 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
| CVE-2026-41675 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-67214 | nanoid |
3.3.11 |
3.3.16 |
| CVE-2026-41673 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-83614 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
| CVE-2026-67213 | nanoid |
3.3.11 |
3.3.18 |
| CVE-2026-2391 | qs |
6.13.0 |
6.14.2 |
| CVE-2026-41674 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2026-73231 | @faker-js/faker |
7.6.0 |
10.5.0 |
| CVE-2026-12151 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-83608 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
| CVE-2026-33895 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-41674 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-73086 | nanoid |
3.3.11 |
3.3.12 |
| CVE-2026-41673 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2026-83614 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-83608 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2025-12816 | node-forge |
1.3.1 |
1.3.2 |
| CVE-2026-83615 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
| CVE-2026-41672 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-34601 | @xmldom/xmldom |
0.7.13 |
0.8.12 |
| CVE-2026-83613 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-83619 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
🟡 Medium · 27 findings
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-48038 | joi |
17.13.3 |
17.13.4 |
| CVE-2023-0842 | xml2js |
0.4.23 |
0.5.0 |
| CVE-2026-8723 | qs |
6.13.0 |
6.15.2 |
| CVE-2025-66030 | node-forge |
1.3.1 |
1.3.2 |
| CVE-2026-82417 | qs |
6.13.0 |
6.16.0 |
| CVE-2026-45822 | decode-uri-component |
0.2.2 |
0.5.0 |
| CVE-2026-41305 | postcss |
8.4.49 |
8.5.10 |
| CVE-2026-16728 | undici |
6.22.0 |
6.28.0 |
| CVE-2026-9679 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-41650 | fast-xml-parser |
4.5.6 |
5.7.0 |
| CVE-2026-33170 | activesupport |
7.2.3 |
7.2.3.1 |
| CVE-2026-1527 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-83610 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
| CVE-2026-54905 | concurrent-ruby |
1.3.3 |
1.3.7 |
| CVE-2025-14762 | aws-sdk-s3 |
1.203.1 |
1.208.0 |
| CVE-2026-33169 | activesupport |
7.2.3 |
7.2.3.1 |
| CVE-2026-15157 | undici |
6.22.0 |
6.28.0 |
| CVE-2026-54171 | excon |
0.112.0 |
1.5.0 |
| CVE-2026-83610 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-47751 | anthropics/claude-code-action |
v1 |
1.0.74 |
| CVE-2026-25765 | faraday |
1.10.4 |
1.10.5 |
| CVE-2026-83611 | @xmldom/xmldom |
0.8.11 |
0.8.15 |
| CVE-2026-53632 | launch-editor |
2.12.0 |
2.14.1 |
| CVE-2026-69153 | postcss |
8.4.49 |
8.5.23 |
| CVE-2026-12590 | body-parser |
1.20.3 |
1.20.6 |
| CVE-2026-16729 | undici |
6.22.0 |
6.28.0 |
| CVE-2026-83611 | @xmldom/xmldom |
0.7.13 |
0.8.15 |
🟢 Low · 6 findings
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-84367 | joi |
17.13.3 |
17.13.5 |
| CVE-2026-11525 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-6733 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-84368 | joi |
17.13.3 |
17.13.6 |
| CVE-2026-54696 | json |
2.16.0 |
2.19.9 |
| CVE-2025-15284 | qs |
6.13.0 |
6.14.1 |
View full analysis in Upwind Console
Scan completed in 7s
Scan history (2 scans)
| Commit | Scanned at | New | Resolved | Net |
|---|---|---|---|---|
f1bdb7d |
2026-09-14 10:42 UTC | +87 | 0 | +87 |
38e067d < |
2026-09-15 02:35 UTC | +87 | 0 | +87 |
Last scanned: 38e067d · 2026-09-15 02:35 UTC
|
| Commit | Scanned at | New | Resolved | Net |
|---|---|---|---|---|
f1bdb7d |
2026-09-14 10:42 UTC | 0 | 0 | 0 |
38e067d < |
2026-09-15 02:35 UTC | 0 | 0 | 0 |
Last scanned: 38e067d · 2026-09-15 02:35 UTC
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #320 +/- ##
=======================================
Coverage 12.31% 12.31%
=======================================
Files 361 361
Lines 9108 9108
Branches 2563 2563
=======================================
Hits 1122 1122
Misses 7985 7985
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
f1bdb7d to
38e067d
Compare
|
/bot create ticket |
|
[Creating Ticket] Preparing https://github.com/sendbird/sendbird-uikit-react-native/actions/runs/34931178815 |
|
[Creating Ticket] In progress https://github.com/sendbird/sdk-deployment/actions/workflows/create-ticket.yml |
|
[Creating Ticket] 🔖 Creating https://sendbird.atlassian.net/browse/SDKRLSD-2276 |
Release v3.12.9
[3.12.9]
Bug Fixes
Included changes
fix: stop relying on instanceof Promise for async effect and voice service resultsfix: use seekTo and millisecond units in the expo-audio player adapterfix: upgrade vulnerable build dependencies(js-yaml 3.15.1/4.3.1, Nx 22.7.7)fix: upgrade js-yaml to patched 3.15.2 / 4.3.2Note:
CHANGELOG_DRAFT.mdonmainstill held the already-released v3.12.8 entries — the v3.12.9 draft written in d3e8758 was reverted by 0574cc7. This PR restores it.Checklist
yarn test: 36 suites / 205 tests,yarn lint: clean)publish-packageworkflowNext Steps
/bot create ticketcomment to create a ticketpublish-packageworkflow in GitHub Actions🤖 Generated with Claude Code