Skip to content

[Snyk] Security upgrade react-router-dom from 6.30.2 to 7.0.0#6416

Closed
caniszczyk wants to merge 2 commits into
masterfrom
snyk-fix-e1a7c21fe79baa8d06b928cbc8a9ffbf
Closed

[Snyk] Security upgrade react-router-dom from 6.30.2 to 7.0.0#6416
caniszczyk wants to merge 2 commits into
masterfrom
snyk-fix-e1a7c21fe79baa8d06b928cbc8a9ffbf

Conversation

@caniszczyk
Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • web/package.json
  • web/yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Cross-site Scripting (XSS)
SNYK-JS-REMIXRUNROUTER-14908530
  646  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-REMIXRUNROUTER-14908530

Signed-off-by: khanhtc1202 <khanhtc1202@gmail.com>
@codecov
Copy link
Copy Markdown

codecov Bot commented Jan 10, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 29.47%. Comparing base (fdec720) to head (f53fc5b).

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #6416      +/-   ##
==========================================
- Coverage   29.48%   29.47%   -0.01%     
==========================================
  Files         593      593              
  Lines       63440    63440              
==========================================
- Hits        18706    18700       -6     
- Misses      43289    43295       +6     
  Partials     1445     1445              
Flag Coverage Δ
. 23.27% <ø> (-0.02%) ⬇️
.-pkg-app-pipedv1-plugin-analysis 32.43% <ø> (ø)
.-pkg-app-pipedv1-plugin-ecs 31.82% <ø> (ø)
.-pkg-app-pipedv1-plugin-kubernetes 58.37% <ø> (ø)
.-pkg-app-pipedv1-plugin-kubernetes_multicluster 61.90% <ø> (ø)
.-pkg-app-pipedv1-plugin-scriptrun 54.83% <ø> (ø)
.-pkg-app-pipedv1-plugin-terraform 37.95% <ø> (ø)
.-pkg-app-pipedv1-plugin-wait 33.04% <ø> (ø)
.-pkg-app-pipedv1-plugin-waitapproval 52.71% <ø> (ø)
.-pkg-plugin-sdk 50.34% <ø> (ø)
.-tool-actions-gh-release 19.23% <ø> (ø)
.-tool-actions-plan-preview 25.51% <ø> (ø)
.-tool-codegen-protoc-gen-auth 0.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions
Copy link
Copy Markdown
Contributor

This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days.

@github-actions github-actions Bot added Stale and removed Stale labels Feb 10, 2026
@github-actions
Copy link
Copy Markdown
Contributor

This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days.

@github-actions github-actions Bot added Stale and removed Stale labels Mar 14, 2026
@github-actions
Copy link
Copy Markdown
Contributor

This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days.

@github-actions github-actions Bot added Stale and removed Stale labels Apr 14, 2026
@khanhtc1202
Copy link
Copy Markdown
Member

Check this after PR #6704 be merged, due to the required NodeJS version update.

Signed-off-by: khanhtc1202 <khanhtc1202@gmail.com>
@khanhtc1202 khanhtc1202 force-pushed the snyk-fix-e1a7c21fe79baa8d06b928cbc8a9ffbf branch from ce8b0cd to f53fc5b Compare April 23, 2026 06:34
@khanhtc1202
Copy link
Copy Markdown
Member

Let's skip this, try update React to v18 first then wait for Snyk to trigger other react-router-dom update, since the target version v7 is incompatible with current React v17 (used in project), and lot of dependecies broken in between.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants