Skip to content

fix(deps): bump react-router-dom to ^7.15.0 (HIGH CVE-2026-42342)#4

Merged
dizhaky merged 1 commit into
mainfrom
fix/dependabot-high-npm-web-20260604
Jun 4, 2026
Merged

fix(deps): bump react-router-dom to ^7.15.0 (HIGH CVE-2026-42342)#4
dizhaky merged 1 commit into
mainfrom
fix/dependabot-high-npm-web-20260604

Conversation

@dizhaky

@dizhaky dizhaky commented Jun 4, 2026

Copy link
Copy Markdown
Owner

Summary

Fixes HIGH severity Dependabot alert NousResearch#26 in the dashboard web app (web/).

Changes

Package From To Alert CVE
react-router 7.14.2 7.17.0 NousResearch#26 CVE-2026-42342

Upstream bump in react-router-dom from ^7.14.1 to ^7.15.0 to pull in the patched react-router.

@github-actions

github-actions Bot commented Jun 4, 2026

Copy link
Copy Markdown

🔎 Lint report: fix/dependabot-high-npm-web-20260604 vs origin/main

ruff

Total: 0 on HEAD, 0 on base (➖ 0)

🆕 New issues: none

✅ Fixed issues: none

Unchanged: 0 pre-existing issues carried over.

ty (type checker)

Total: 9086 on HEAD, 9086 on base (➖ 0)

🆕 New issues: none

✅ Fixed issues: none

Unchanged: 4836 pre-existing issues carried over.

Diagnostics are surfaced as warnings — this check never fails the build.

@github-actions

github-actions Bot commented Jun 4, 2026

Copy link
Copy Markdown

⚠️ npm lockfile hash out of date

Checked against commit 52ea25d (PR head at check time).

The hash = "sha256-..." line in these nix files no longer matches the committed package-lock.json:

Apply the fix

  • Apply lockfile fix — tick to push a commit with the correct hashes to this PR branch
  • Or run the Nix Lockfile Fix workflow manually (pass PR #4)
  • Or locally: nix run .#fix-lockfiles and commit the diff

@dizhaky dizhaky merged commit b514c8b into main Jun 4, 2026
12 of 14 checks passed
@dizhaky dizhaky deleted the fix/dependabot-high-npm-web-20260604 branch June 4, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant