Skip to content

chore(deps): clear npm audit highs — react-router v8 + transitive bumps - #203

Merged
Anuraj-dev merged 1 commit into
mainfrom
chore/audit-fix-brace-expansion-tar
Jul 30, 2026
Merged

Anuraj-dev merged 1 commit into
mainfrom
chore/audit-fix-brace-expansion-tar

Conversation

@Anuraj-dev

Copy link
Copy Markdown
Owner

Why

Two advisory waves published today turned the npm audit (high) CI gate red on every open PR (#198–#200 all fail identically on main's lockfile):

  • brace-expansion (high, GHSA-mh99-v99m-4gvg) + tar (moderate) — plain lockfile bump.
  • react-router: GHSA-qwww-vcr4-c8h2 (RSC-mode CSRF) covers 7.12.0–8.2.0, and the older advisory batch covers ≤7.17.0 — no 7.x version is clean. react-router@8.3.0 is the only clear release.

What

  • npm audit fix for brace-expansion/tar (root lockfile only)
  • Client migrated react-router-dom@^7 → react-router@^8.3.0. The dom package is a v7 re-export shim retired in v8, so this is an import-path swap across 13 files + dependency rename; every API used is unchanged. Per-workspace lockfiles untouched (CI cache keys).

Verification

  • npm audit --audit-level=high: 0 vulnerabilities
  • npm run typecheck: all four workspaces clean
  • npm test -w client: 27 files, 186 tests green
  • Full CI (incl. Playwright E2E) validates the router swap end-to-end

Unblocks the merge gate for #198, #199, #200.

Two advisory waves landed 2026-07-30 and turned the npm-audit CI gate red on
every branch:
- brace-expansion (high, GHSA-mh99-v99m-4gvg) and tar (moderate) — fixed by
  a plain lockfile bump.
- react-router: the new RSC CSRF advisory (GHSA-qwww-vcr4-c8h2) covers
  7.12.0–8.2.0 while the older XSS/RCE batch covers <=7.17.0, so no 7.x
  release is clean. Only react-router@8.3.0 clears both.

Migrated the client from react-router-dom@7 to react-router@8.3.0: in v7+
react-router-dom is a re-export shim and v8 retires it, so this is a pure
import-path swap (13 files) plus the dependency rename. All router APIs used
(BrowserRouter, Routes, Route, Navigate, Memory/useNavigate/useParams/
useLocation/useSearchParams, Link) are unchanged.

npm audit: 0 vulnerabilities. Typecheck all workspaces + full client suite
(27 files, 186 tests) green locally.
@vercel

vercel Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
a-meet Ready Ready Preview Jul 30, 2026 2:33pm

@Anuraj-dev
Anuraj-dev merged commit ac73977 into main Jul 30, 2026
22 of 23 checks passed
@Anuraj-dev
Anuraj-dev deleted the chore/audit-fix-brace-expansion-tar branch July 30, 2026 14:37

This branch was successfully deployed

1 active deployment
Preview — c0c85af0 Deployed Jul 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant