[Snyk] Security upgrade @expo/config-plugins from 4.1.5 to 54.0.3#111
[Snyk] Security upgrade @expo/config-plugins from 4.1.5 to 54.0.3#111snyk-io[bot] wants to merge 1 commit intomainfrom
Conversation
…/package.json & ExpoImplementationEAS/config-plugins/cs-expo-react-native-bridge/yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MINIMATCH-15309438
|
This is a major version upgrade from v4 to v54, which corresponds to a very significant Expo SDK migration (e.g., from ~SDK 44 to SDK 54). This update includes numerous fundamental and breaking changes that will require significant developer action. Key Breaking Changes:
Recommendation: This upgrade cannot be treated as a simple package update. It must be handled as a comprehensive Expo SDK migration. Developers should follow the official Expo upgrade guides for each SDK version between their current version and SDK 54. Due to the scale of the changes, extensive testing and refactoring of any custom config plugins will be necessary.
|
Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
ExpoImplementationEAS/config-plugins/cs-expo-react-native-bridge/package.jsonExpoImplementationEAS/config-plugins/cs-expo-react-native-bridge/yarn.lockNote for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarnto update the contents of the./yarn/cachedirectory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-MINIMATCH-15309438
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)