Skip to content

Commit 42ee1be

Browse files
underaclaude
andcommitted
build(deps): bump react-router from 7.15.1 to 7.18.2 in /frontend
Closes four open Dependabot advisories, all patched in 7.18.0: - Unauthenticated DoS via inefficient route matching - Open redirect via backslash in <Link>/useNavigate (CVE-2025-68470 bypass) - Arbitrary constructor injection in deserializeErrors() - RSCErrorHandler missing protocol validation (XSS) Supersedes #726, which proposed the 8.3.0 major. v8 is not required for any of these fixes and would additionally impose Node >=22.22.0, React >=19.2.7, ESM-only distribution and an ES2022 target. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent f24c23a commit 42ee1be

2 files changed

Lines changed: 5 additions & 5 deletions

File tree

frontend/package-lock.json

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

frontend/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@
4141
"react-icons": "^5.5.0",
4242
"react-intersection-observer": "^10.0.3",
4343
"react-modern-drawer": "^1.4.0",
44-
"react-router": "^7.13.0",
44+
"react-router": "^7.18.2",
4545
"react-select": "^5.10.2",
4646
"swagger-ui-react": "^5.31.2",
4747
"uuid": "^14.0.0"

0 commit comments

Comments
 (0)