fix(deps): update dependency expo to v48 [security]#104
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
4cee980 to
99ab4df
Compare
99ab4df to
a2bb909
Compare
a2bb909 to
2b1d186
Compare
2b1d186 to
19bf51a
Compare
19bf51a to
f842e9f
Compare
f842e9f to
5c6de53
Compare
5c6de53 to
fdf6efb
Compare
fdf6efb to
f06f765
Compare
d2aea12 to
82565f8
Compare
82565f8 to
0a15a6f
Compare
0a15a6f to
e0a9ab8
Compare
dbb3c3c to
e861ea8
Compare
e861ea8 to
7d182b2
Compare
820451a to
c6bdb22
Compare
c6bdb22 to
d19b050
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
36.0.2→48.0.0Expo SDK has an OAuth vulnerability
CVE-2023-28131 / GHSA-wr5g-q49g-548w
More information
Details
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
expo/expo (expo)
v48.0.0Compare Source
This version does not introduce any user-facing changes.
v47.0.14Compare Source
v47.0.13Compare Source
v47.0.12Compare Source
v47.0.11Compare Source
v47.0.10Compare Source
v47.0.9Compare Source
v47.0.8Compare Source
v47.0.7Compare Source
v47.0.6Compare Source
v47.0.5Compare Source
v47.0.4Compare Source
v47.0.3Compare Source
v47.0.2Compare Source
v47.0.1Compare Source
This version does not introduce any user-facing changes.
v47.0.0Compare Source
🐛 Bug fixes
v46.0.21Compare Source
v46.0.20Compare Source
v46.0.19Compare Source
v46.0.18Compare Source
v46.0.17Compare Source
v46.0.16Compare Source
v46.0.15Compare Source
v46.0.14Compare Source
v46.0.13Compare Source
v46.0.12Compare Source
v46.0.11Compare Source
v46.0.10Compare Source
v46.0.9Compare Source
v46.0.8Compare Source
v46.0.7Compare Source
v46.0.6Compare Source
v46.0.5Compare Source
v46.0.4Compare Source
v46.0.3Compare Source
v46.0.2Compare Source
v46.0.1Compare Source
This version does not introduce any user-facing changes.
v46.0.0Compare Source
This version does not introduce any user-facing changes.
v45.0.8Compare Source
v45.0.7Compare Source
v45.0.4Compare Source
v45.0.3Compare Source
v45.0.2Compare Source
v45.0.1Compare Source
v45.0.0Compare Source
This version does not introduce any user-facing changes.
v44.0.6Compare Source
v44.0.5Compare Source
v44.0.4Compare Source
v44.0.3Compare Source
v44.0.2Compare Source
v44.0.1Compare Source
v44.0.0Compare Source
v43.0.5Compare Source
v43.0.4Compare Source
v43.0.3Compare Source
v43.0.2Compare Source
v43.0.1Compare Source
v43.0.0Compare Source
v42.0.5Compare Source
v42.0.4Compare Source
v42.0.3Compare Source
v42.0.2Compare Source
v42.0.1Compare Source
v42.0.0Compare Source
v41.0.1Compare Source
v41.0.0Compare Source
v40.0.1Compare Source
v40.0.0Compare Source
v39.0.5Compare Source
v39.0.4Compare Source
v39.0.3Compare Source
v39.0.2Compare Source
v39.0.1Compare Source
v39.0.0Compare Source
v38.0.11Compare Source
v38.0.10Compare Source
v38.0.9Compare Source
v38.0.8Compare Source
v38.0.7Compare Source
v38.0.6Compare Source
v38.0.5Compare Source
v38.0.4Compare Source
v38.0.3Compare Source
v38.0.2Compare Source
v38.0.1Compare Source
v38.0.0Compare Source
v37.0.12Compare Source
v37.0.11Compare Source
v37.0.10Compare Source
v37.0.9Compare Source
v37.0.8Compare Source
v37.0.7Compare Source
v37.0.6Compare Source
v37.0.5Compare Source
v37.0.4Compare Source
v37.0.3Compare Source
v37.0.2Compare Source
v37.0.1Compare Source
v37.0.0Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.