Skip to content

sentry/react-native update 1.3.9#113

Merged
brentvatne merged 1 commit intoexpo:masterfrom
nabettu:feature/sentry-update1.3.9
May 22, 2020
Merged

sentry/react-native update 1.3.9#113
brentvatne merged 1 commit intoexpo:masterfrom
nabettu:feature/sentry-update1.3.9

Conversation

@nabettu
Copy link
Copy Markdown
Contributor

@nabettu nabettu commented May 22, 2020

Why

Old @sentry/react-native has security issues. that could potentially lead to access to source map in applications at iOS SDK.

Therefore, it is necessary to update to a benign version.

@brentvatne
Copy link
Copy Markdown
Member

brentvatne commented May 22, 2020

"^1.0.0" is equivalent to "^1.3.9" :) you would need to clear your lockfile to get this upgrade though. that said, it doesn't hurt to bump it so that when folks update @sentry/expo they definitely get this latest version

Screen Shot 2020-05-22 at 12 16 25 PM

edit: could you link me to a resource with more info about this vulernability?

@brentvatne brentvatne merged commit c8c67e8 into expo:master May 22, 2020
@nabettu
Copy link
Copy Markdown
Contributor Author

nabettu commented May 23, 2020

@brentvatne
Sorry, I just received an email from Sentry, but it seems that Sentry itself has not been published to Blog etc. probably due to a security problem.

The text of the email is the same as the text written in this issue.

#112

@brentvatne
Copy link
Copy Markdown
Member

this actually doesn't seem to impact sentry-expo in managed expo applications because we don't use the native sdk, we just use the js portions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants