deps: bump @tanstack/react-router from 1.168.24 to 1.168.25 in /web#148
Conversation
Bumps [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) from 1.168.24 to 1.168.25. - [Release notes](https://github.com/TanStack/router/releases) - [Changelog](https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/TanStack/router/commits/@tanstack/react-router@1.168.25/packages/react-router) --- updated-dependencies: - dependency-name: "@tanstack/react-router" dependency-version: 1.168.25 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM, dependabot patch bump.
Extended reasoning...
Overview
This is a Dependabot-generated patch bump of @tanstack/react-router from 1.168.24 to 1.168.25 in the web/ workspace. The only transitive change is @tanstack/router-core going from 1.168.16 to 1.168.17. web/package.json and web/package-lock.json are the only modified files.
Security risks
None apparent. Both packages are MIT-licensed and come from the established TanStack registry. The patch release contains only a re-export bump of router-core; no new transitive dependencies were added.
Level of scrutiny
Low. This is a routine semver-patch dependency bump, exactly the kind of mechanical change suitable for shadow approval.
Other factors
No bugs were flagged by the bug hunting system, and the change is contained entirely to the frontend lockfile/manifest with no source code touched.
Bumps @tanstack/react-router from 1.168.24 to 1.168.25.
Changelog
Sourced from @tanstack/react-router's changelog.
Commits
1285422ci: changeset releaseDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)