chore(deps): update dependency react-router [security]#7604
Open
backstage-goalie[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): update dependency react-router [security]#7604backstage-goalie[bot] wants to merge 1 commit intomainfrom
backstage-goalie[bot] wants to merge 1 commit intomainfrom
Conversation
7ccc476 to
223558f
Compare
223558f to
3132e4c
Compare
3132e4c to
0013cf6
Compare
0013cf6 to
6af100b
Compare
6af100b to
5408b69
Compare
5408b69 to
d4b10ec
Compare
d4b10ec to
a9e19c5
Compare
a9e19c5 to
e192a7e
Compare
e192a7e to
cc1ad06
Compare
cc1ad06 to
9f39d75
Compare
9f39d75 to
c3da919
Compare
c3da919 to
4d8b56c
Compare
4d8b56c to
4cfcf74
Compare
4cfcf74 to
2ee6086
Compare
2ee6086 to
4c2cc66
Compare
4c2cc66 to
4e5e0ab
Compare
4e5e0ab to
8bbd6cd
Compare
8bbd6cd to
604fe1a
Compare
604fe1a to
8e62e3a
Compare
8e62e3a to
1600cb5
Compare
1600cb5 to
4d6d3a1
Compare
4d6d3a1 to
79aa8f7
Compare
79aa8f7 to
27f06f1
Compare
27f06f1 to
3abe362
Compare
3abe362 to
49a3b78
Compare
49a3b78 to
485e5e0
Compare
485e5e0 to
64a7cb3
Compare
64a7cb3 to
4974882
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
4974882 to
e589fe6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.26.2→6.30.26.23.1→6.30.26.26.1→6.30.26.24.0→6.30.26.28.0→6.30.26.23.0→6.30.26.26.0→6.30.26.29.0→6.30.26.27.0→6.30.26.30.2→6.30.36.30.0→6.30.26.25.1→6.30.26.0.0-beta.0 || ^6.3.0→6.30.2 ^6.30.26.30.1→6.30.26.24.1→6.30.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
React Router has unexpected external redirect via untrusted paths
CVE-2025-68470 / GHSA-9jcx-v3wj-wh4m
More information
Details
An attacker-supplied path can be crafted so that when a React Router application navigates to it via
navigate(),<Link>, orredirect(), the app performs a navigation/redirect to an external URL. This is only an issue if developers pass untrusted content into navigation paths in their application code.Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
remix-run/react-router (react-router)
v6.30.2: v6.30.2Compare Source
See the changelog for release notes: https://github.com/remix-run/react-router/blob/v6/CHANGELOG.md#v6302
v6.30.1: v6.30.1Compare Source
See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v6301
v6.30.0: v6.30.0Compare Source
See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v6300
v6.29.0: v6.29.0Compare Source
See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v6290
v6.28.2: v6.28.2Compare Source
See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v6282
v6.28.1: v6.28.1Compare Source
See the changelog for release notes: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v6281
v6.28.0Compare Source
Minor Changes
json/deferin favor of returning raw objectsPatch Changes
@remix-run/router@1.21.0v6.27.0Compare Source
Minor Changes
unstable_patchRoutesOnNavigation(#11973)PatchRoutesOnNavigationFunctionArgstype for convenience (#11967)unstable_dataStrategy(#11974)unstable_flushSyncoption for navigations and fetchers (#11989)unstable_viewTransitionoption for navigations and the correspondingunstable_useViewTransitionStatehook (#11989)Patch Changes
Fix bug when submitting to the current contextual route (parent route with an index child) when an
?indexparam already exists from a prior submission (#12003)Fix
useFormActionbug - when removing?indexparam it would not keep other non-Remixindexparams (#12003)Fix types for
RouteObjectwithinPatchRoutesOnNavigationFunction'spatchmethod so it doesn't expect agnostic route objects passed topatch(#11967)Updated dependencies:
@remix-run/router@1.20.0Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.