Skip to content

[Snyk] Security upgrade react-router-dom from 7.3.0 to 7.5.2#677

Closed
wkylin wants to merge 1 commit into
mainfrom
snyk-fix-1dcc4a51b26f31fd808374f14d2cb69f
Closed

[Snyk] Security upgrade react-router-dom from 7.3.0 to 7.5.2#677
wkylin wants to merge 1 commit into
mainfrom
snyk-fix-1dcc4a51b26f31fd808374f14d2cb69f

Conversation

@wkylin
Copy link
Copy Markdown
Owner

@wkylin wkylin commented Apr 27, 2025

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Insufficient Verification of Data Authenticity
SNYK-JS-REACTROUTER-9804426
  833  
high severity Improper Handling of Exceptional Conditions
SNYK-JS-REACTROUTER-9804420
  828  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 27, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
pro-react-admin ✅ Ready (Inspect) Visit Preview 💬 Add feedback Apr 27, 2025 5:45am

@what-the-diff
Copy link
Copy Markdown

what-the-diff Bot commented Apr 27, 2025

PR摘要

  • 更新了react-router-dom的版本
    我们在package.jsonpackage-lock.json中把react-router-dom的版本从^7.2.0更新到了^7.5.2
  • 更新了react-router的版本
    我们在package-lock.json中把react-router的版本从7.3.0更新到了7.5.2
  • 更改了package-lock.json中几个包的解析URL
    我们把package-lock.json中的一些包(包括cookiereact-routerreact-router-dom)的解析URL从npmmirror.com改到了npmjs.org
  • package-lock.json中移除了@types/cookie的条目
    我们移除了package-lock.json@types/cookie(版本0.6.0)的条目。

@sonarqubecloud
Copy link
Copy Markdown

@wkylin wkylin closed this Apr 27, 2025
@wkylin wkylin deleted the snyk-fix-1dcc4a51b26f31fd808374f14d2cb69f branch May 8, 2025 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants