chore: added new privacy file and identified reason for using privacy APIs#9124
chore: added new privacy file and identified reason for using privacy APIs#9124
Conversation
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #9124 +/- ##
=======================================
Coverage 45.98% 45.98%
=======================================
Files 1273 1273
Lines 31342 31342
Branches 3213 3213
=======================================
Hits 14414 14414
Misses 16079 16079
Partials 849 849 ☔ View full report in Codecov by Sentry. |
|
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/@sentry/react-native@5.11.1 |
|
👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎ This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring: Next stepsTake a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with |
|
|
@SocketSecurity ignore npm/@sentry-internal/tracing@7.100.1 All new packages are part of the Sentry upgrade and are expected. |
|
|
Cal-L
left a comment
There was a problem hiding this comment.
Failing e2e doesn't seem related to this PR. Lgtm
|




Description
This PR adds a new privacy file identifying why the app is using specific privacy APIs.
These mentions in the manifest:
Are the modules/functions that are associated with the required declarations in the manifest.
Sentry was also updated due to bug with duplicate Privacy Manifests in older versions.
Related issues
Fixes
Manual testing steps
Screenshots/Recordings
Before
After
Pre-merge author checklist
Pre-merge reviewer checklist