Replies: 1 comment
|
Closing this issue because the fix was backported to React Router 7.18.2: Thank you! |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hello!
Could you please consider backporting the fix for GHSA-qwww-vcr4-c8h2
(commit 7a71c72, released in react-router 8.3.0) to the supported 7.x line?
Our application uses React Router in Declarative Mode only and does not use
unstable RSC APIs. However, our security gate blocks releases on any High
advisory.
Upgrading to React Router 8 currently requires React 19.2.7+, while our
application and several dependencies are on React 18. A patched 7.x release
would allow us to remediate the advisory without a full React 19 migration.
Thank you!
All reactions