## go-webauthn/webauthn — v0.18.1…v0.18.2

_13 commits._

### Features
- **feat(protocol): determine fido-u2f attestation type from metadata (#798)** (ccbbb4b)
- **feat(protocol): validate authenticator data against metadata (#793)** (1ee00cf)

### Fixes
- **fix(protocol): validate fido-u2f credential curve and certificate validity (#802)** (55d49f8)
- **fix(protocol): convey safetynet attestation trust path (#800)** (5f8a38c)
- **fix(protocol): accept anonca attestation trust anchors (#801)** (b1dfbf2)
- **fix(protocol): validate safetynet version and response age (#799)** (dda068d)
- **fix(protocol): validate tpm aik certificate validity period (#797)** (9ab858d)
- **fix(webauthn): require authorization to initialize uv (#795)** (597882d)
- **fix(webauthn): validate session challenge when finishing ceremonies (#794)** (bbe2902)

### Backend
- **release: v0.18.2 (#803)** (a4c6fc6)

### Chore
- **build(deps): update github/codeql-action action to v4.38.1 (#796)** (3f8af2b)
- **build(deps): update codecov/codecov-action action to v7.1.1 (#791)** (ee8d3ca)
- **build(deps): update module github.com/fxamacker/cbor/v2 to v2.9.4 (#790)** (f88bd7f)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/go-webauthn/webauthn?utm_source=github-action)._