Commit 6de3712
authored
fix(frontend): bump react-router-dom to ^7.15.0 to clear Mend CVEs (#267)
Bumps react-router-dom from ^7.13.1 to ^7.15.0 in
altk_evolve/frontend/ui to remediate six Mend-flagged advisories in the
transitive react-router dependency. 7.15.0 is the highest fix floor
across the set (CVE-2026-42342 __manifest ReDoS). Resolved lock now
pins react-router/react-router-dom at 7.17.0.
Cleared CVEs:
- CVE-2026-34077
- CVE-2026-40181
- CVE-2026-42342 (highest fix floor: 7.15.0, __manifest ReDoS)
- CVE-2026-33245
- CVE-2026-42211
- CVE-2026-332441 parent a8a6fe4 commit 6de3712
2 files changed
Lines changed: 42 additions & 157 deletions
0 commit comments