Skip to content

chore(deps): bump packages to Expo SDK 57 recommended versions - #181

Merged
morepriyam merged 2 commits into
mainfrom
chore/expo-sdk57-patches
Sep 9, 2026
Merged

morepriyam merged 2 commits into
mainfrom
chore/expo-sdk57-patches

Conversation

@morepriyam

@morepriyam morepriyam commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #180. Runs npx expo install --fix so expo-doctor passes 21/21 checks: expo 57.0.12 → 57.0.21, react-native 0.86.2 → 0.86.3, and the 24 expo-* / @expo/ui / eslint-config-expo packages that were behind the SDK 57 patch line.

Side effect: @expo/metro 56.0.2 pulls metro 0.84.5, which no longer depends on image-size, so both image-size alerts (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) close. The only advisory left after this is decode-uri-component via expo-router's query-string@7 pin, which is waiting on upstream (see #180).

Metro ends up with two copies: 0.84.6 at the root for @react-native/community-cli-plugin's ^0.84.3 range, and 0.84.5 nested under @expo/metro's exact pin. Expo CLI only bundles with its own nested copy, so this is bloat rather than a behaviour risk.

Verification

  • jest: 126 passed, 16 skipped
  • tsc --noEmit, expo lint
  • expo-doctor: 21/21
  • drizzle-kit check
  • expo export --platform ios
  • rm -rf node_modules && npm ci reproduces the lockfile with no diff

Merge order: #180 first, then this one (GitHub retargets it to main automatically), then rebase #175.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the app’s Expo SDK 57 ecosystem dependencies to the current SDK-recommended patch versions, primarily to keep expo-doctor clean and eliminate remaining transitive security advisories via Metro’s updated dependency tree.

Changes:

  • Bump Expo SDK (expo) and a set of expo-* modules to newer SDK 57 patch releases.
  • Bump React Native patch version (react-native 0.86.2 → 0.86.3) and update eslint-config-expo.
  • Refresh package-lock.json to reflect the new dependency graph (including Metro/CLI transitive changes).

Reviewed changes

Copilot reviewed 2 out of 9 changed files in this pull request and generated no comments.

File Description
package.json Updates Expo/React Native-related dependency versions to SDK 57 recommended patches.
package-lock.json Regenerates the lockfile to match the updated dependency set (Metro/Expo CLI/transitives).
Files not reviewed (1)
  • screenshots/frame/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

`npx expo install --fix`: expo 57.0.12 -> 57.0.21, react-native 0.86.2 -> 0.86.3, and the 24
expo-* / @expo/ui / eslint-config-expo packages expo-doctor flagged as behind the SDK 57 patch
line. expo-doctor now passes 21/21 checks.

Side effect: @expo/metro 56.0.2 pulls metro 0.84.5, which no longer depends on image-size, so the
two image-size advisories (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) are gone. The only advisory
left in `npm audit` is decode-uri-component via expo-router's query-string@7 pin. metro now has two
copies (0.84.6 at the root for @react-native/community-cli-plugin's ^0.84.3 range, 0.84.5 nested
under @expo/metro's exact pin); Expo CLI only bundles with its own nested copy.

Verified: jest, tsc, expo lint, expo-doctor, drizzle-kit check, expo export --platform ios,
clean npm ci reproduces the lockfile.
@morepriyam
morepriyam force-pushed the chore/expo-sdk57-patches branch from 1eb1977 to d827b43 Compare September 9, 2026 14:29
Copilot AI review requested due to automatic review settings September 9, 2026 14:29

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated 2 comments.

Comment thread package.json
Comment thread package.json
metro 0.84.5+ requires Node ^20.19.4 || ^22.13.0 || ^24.3.0, so declare that in engines (CI already
runs the latest Node 20). Move expo-asset, expo-constants, expo-file-system and expo-font ranges up
to the SDK 57 patch versions the lockfile already resolves to, so package.json and the lockfile
agree.
Copilot AI review requested due to automatic review settings September 9, 2026 14:37
@morepriyam
morepriyam changed the base branch from fix/dependency-vulns to main September 9, 2026 14:37
@morepriyam
morepriyam merged commit e5f2101 into main Sep 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.

morepriyam added a commit that referenced this pull request Sep 9, 2026
Patch release carrying the dependency advisory fixes (#180, #181) and the segment-thumb
strand fix (#175). Android versionCode base moves to 20001 so CI-stamped codes stay above
every 2.0.0 build. Prebuild carries both into the native projects.
@morepriyam
morepriyam deleted the chore/expo-sdk57-patches branch September 10, 2026 14:40
@morepriyam morepriyam self-assigned this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants