Skip to content

Patch the consumer UI routing library advisory - #533

Open
ecv wants to merge 1 commit into
mainfrom
fix/react-router-advisory
Open

ecv wants to merge 1 commit into
mainfrom
fix/react-router-advisory

Conversation

@ecv

@ecv ecv commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Summary

The consumer portal plugin shipped a routing library version with a known high-severity security advisory.

This moves it to the latest patch release that contains the fix. No other dependency changes.

Test plan

  • Frozen install, typecheck, build and unit tests pass for the plugin

Related to datum-cloud/infra#6691

The consumer portal plugin pinned react-router 7.18.0, inside the range
affected by GHSA-qwww-vcr4-c8h2 (>=7.12.0 <7.18.2). Move to 7.18.4, the
latest 7.x, which includes the fix.

Key changes:
- Pin react-router to 7.18.4 in package.json, matching the existing
  exact-pin style
- Refresh bun.lock for that single package; no other dependency moves
@ecv ecv changed the title fix: Update react-router in the consumer portal plugin Patch the consumer UI routing library advisory Oct 3, 2026
@ecv
ecv marked this pull request as ready for review October 3, 2026 03:55
@ecv
ecv requested a review from a team as a code owner October 3, 2026 03:55

@kevwilliams kevwilliams left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sound. Patch bump of react-router (7.18.0 to 7.18.4) in the consumer UI plugin, clearing a high-severity routing library advisory. Lockfile and package.json both updated consistently, no other dependency changes. CI green, tiny diff.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants