Skip to content

Upgrade React Router packages for CVE fixes#1092

Merged
kentcdodds merged 4 commits into
mainfrom
cursor/upgrade-react-router-cves-b3c9
Jun 2, 2026
Merged

Upgrade React Router packages for CVE fixes#1092
kentcdodds merged 4 commits into
mainfrom
cursor/upgrade-react-router-cves-b3c9

Conversation

@kentcdodds
Copy link
Copy Markdown
Member

@kentcdodds kentcdodds commented Jun 2, 2026

Upgrades the direct React Router package family and related direct dev tools:

  • react-router to 7.16.0
  • @react-router/dev to 7.16.0
  • @react-router/node to 7.16.0
  • @react-router/express to 7.16.0
  • react-router-auto-routes to 0.8.4
  • react-router-devtools to 6.2.1

Also updates the auth callback loader test helper for React Router 7.16's server loader args (url/pattern).

Test Plan

  • npm list react-router @react-router/dev @react-router/node @react-router/express react-router-devtools react-router-auto-routes --depth=1
  • node --input-type=module -e "...npm audit --json summary..." (still exits with existing audit findings; the React Router CVE package family is resolved to 7.16.0. Remaining audit entries include unrelated packages plus react-router-devtools's existing react-d3-tree/uuid advisory, for which npm suggests downgrading to react-router-devtools@1.0.0 rather than a newer patched release.)
  • set -a && . ./.env.example && set +a && npx prisma migrate deploy && npx prisma generate --sql && npm run typecheck && npm run build && npm run test -- --run

Checklist

  • Tests updated
  • Docs updated

Screenshots

N/A - dependency/security update only.

Open in Web Open in Cursor 

cursoragent and others added 4 commits June 2, 2026 16:06
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds kentcdodds marked this pull request as ready for review June 2, 2026 16:13
@kentcdodds kentcdodds merged commit faaa217 into main Jun 2, 2026
7 checks passed
@kentcdodds kentcdodds deleted the cursor/upgrade-react-router-cves-b3c9 branch June 2, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants