Commit 42ee1be
build(deps): bump react-router from 7.15.1 to 7.18.2 in /frontend
Closes four open Dependabot advisories, all patched in 7.18.0:
- Unauthenticated DoS via inefficient route matching
- Open redirect via backslash in <Link>/useNavigate (CVE-2025-68470 bypass)
- Arbitrary constructor injection in deserializeErrors()
- RSCErrorHandler missing protocol validation (XSS)
Supersedes #726, which proposed the 8.3.0 major. v8 is not required for
any of these fixes and would additionally impose Node >=22.22.0,
React >=19.2.7, ESM-only distribution and an ES2022 target.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent f24c23a commit 42ee1be
2 files changed
Lines changed: 5 additions & 5 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
0 commit comments