chore(deps): bump packages to Expo SDK 57 recommended versions - #181
Merged
Merged
Conversation
morepriyam
force-pushed
the
fix/dependency-vulns
branch
from
September 9, 2026 14:26
c5017f1 to
f73d9b3
Compare
There was a problem hiding this comment.
Pull request overview
Updates the app’s Expo SDK 57 ecosystem dependencies to the current SDK-recommended patch versions, primarily to keep expo-doctor clean and eliminate remaining transitive security advisories via Metro’s updated dependency tree.
Changes:
- Bump Expo SDK (
expo) and a set ofexpo-*modules to newer SDK 57 patch releases. - Bump React Native patch version (
react-native0.86.2 → 0.86.3) and updateeslint-config-expo. - Refresh
package-lock.jsonto reflect the new dependency graph (including Metro/CLI transitive changes).
Reviewed changes
Copilot reviewed 2 out of 9 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| package.json | Updates Expo/React Native-related dependency versions to SDK 57 recommended patches. |
| package-lock.json | Regenerates the lockfile to match the updated dependency set (Metro/Expo CLI/transitives). |
Files not reviewed (1)
- screenshots/frame/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
`npx expo install --fix`: expo 57.0.12 -> 57.0.21, react-native 0.86.2 -> 0.86.3, and the 24 expo-* / @expo/ui / eslint-config-expo packages expo-doctor flagged as behind the SDK 57 patch line. expo-doctor now passes 21/21 checks. Side effect: @expo/metro 56.0.2 pulls metro 0.84.5, which no longer depends on image-size, so the two image-size advisories (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) are gone. The only advisory left in `npm audit` is decode-uri-component via expo-router's query-string@7 pin. metro now has two copies (0.84.6 at the root for @react-native/community-cli-plugin's ^0.84.3 range, 0.84.5 nested under @expo/metro's exact pin); Expo CLI only bundles with its own nested copy. Verified: jest, tsc, expo lint, expo-doctor, drizzle-kit check, expo export --platform ios, clean npm ci reproduces the lockfile.
morepriyam
force-pushed
the
chore/expo-sdk57-patches
branch
from
September 9, 2026 14:29
1eb1977 to
d827b43
Compare
metro 0.84.5+ requires Node ^20.19.4 || ^22.13.0 || ^24.3.0, so declare that in engines (CI already runs the latest Node 20). Move expo-asset, expo-constants, expo-file-system and expo-font ranges up to the SDK 57 patch versions the lockfile already resolves to, so package.json and the lockfile agree.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacked on #180. Runs
npx expo install --fixso expo-doctor passes 21/21 checks: expo 57.0.12 → 57.0.21, react-native 0.86.2 → 0.86.3, and the 24expo-*/@expo/ui/eslint-config-expopackages that were behind the SDK 57 patch line.Side effect:
@expo/metro56.0.2 pulls metro 0.84.5, which no longer depends onimage-size, so both image-size alerts (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) close. The only advisory left after this isdecode-uri-componentvia expo-router'squery-string@7pin, which is waiting on upstream (see #180).Metro ends up with two copies: 0.84.6 at the root for
@react-native/community-cli-plugin's^0.84.3range, and 0.84.5 nested under@expo/metro's exact pin. Expo CLI only bundles with its own nested copy, so this is bloat rather than a behaviour risk.Verification
jest: 126 passed, 16 skippedtsc --noEmit,expo lintexpo-doctor: 21/21drizzle-kit checkexpo export --platform iosrm -rf node_modules && npm cireproduces the lockfile with no diffMerge order: #180 first, then this one (GitHub retargets it to
mainautomatically), then rebase #175.