-
-
Notifications
You must be signed in to change notification settings - Fork 119
Bump react-router-dom from 5.0.1 to 6.10.0 #167
Conversation
Bumps [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) from 5.0.1 to 6.10.0. - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@6.10.0/packages/react-router-dom) --- updated-dependencies: - dependency-name: react-router-dom dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
New dependency changes detected. Learn more about Socket for GitHub ↗︎ 🚨 Potential security issues found in this pull request. To accept the risk, merge this PR and you will not be notified again. Bot CommandsTo ignore an alert, reply with a comment starting with
|
| Package | Module | Location | Source |
|---|---|---|---|
| @remix-run/router@1.5.0 (added) | globalThis["fetch"] | dist/router.cjs.js | package.json via react-router-dom@6.10.0 |
| @remix-run/router@1.5.0 (added) | globalThis["fetch"] | dist/router.js | package.json via react-router-dom@6.10.0 |
| @remix-run/router@1.5.0 (added) | globalThis["fetch"] | dist/router.umd.js | package.json via react-router-dom@6.10.0 |
⚠️ URL strings
Package contains fragments of external URLs or IP addresses, which may indicate that it covertly exfiltrates data.
Avoid using packages that make connections to the network, since this helps to leak data.
⚠️ Environment variable access
Package accesses environment variables, which may be a sign of credential stuffing or data theft.
Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.
| Package | ENV Vars | Location | Source |
|---|---|---|---|
| resolve-pathname@3.0.0 (upgraded) | index.js | package.json via react-router-transition@1.3.0 |
|
| resolve-pathname@3.0.0 (upgraded) | index.js | package.json via react-router-transition@1.3.0 |
|
| value-equal@1.0.1 (upgraded) | index.js | package.json via react-router-transition@1.3.0 |
|
| value-equal@1.0.1 (upgraded) | index.js | package.json via react-router-transition@1.3.0 |
⚠️ Minified code
This package contains minified code. This may be harmless in some cases where minified code is included in packaged libraries, however packages on npm should not minify code.
In many cases minified code is harmless, however minified code can be used to hide a supply chain attack. Consider not shipping minified code on npm.
| Package | Confidence | Location | Source |
|---|---|---|---|
| history@4.10.1 (upgraded) | 1.00 | cjs/history.min.js | package.json via react-router-transition@1.3.0 |
| react-router@6.10.0 (upgraded) | 1.00 | dist/umd/react-router.production.min.js | package.json via react-router-dom@6.10.0 |
| react-router-dom@6.10.0 (upgraded) | 1.00 | dist/umd/react-router-dom.production.min.js | package.json |
⚠️ No tests
Package does not have any tests. This is a strong signal of a poorly maintained or low quality package.
Add tests and publish a new version of the package. Consumers may look for an alternative package with better testing.
| Package | Location | Source |
|---|---|---|
| @remix-run/router@1.5.0 (added) | package.json | package.json via react-router-dom@6.10.0 |
| react-router@6.10.0 (upgraded) | package.json | package.json via react-router-dom@6.10.0 |
| react-router-dom@6.10.0 (upgraded) | package.json | package.json |
⚠️ Chronological version anomaly
Semantic versions published out of chronological order.
This could either indicate dependency confusion or a patched vulnerability.
| Package | Previous Chronological | Previous Semver | Source |
|---|---|---|---|
| @remix-run/router@1.5.0 (added) | @remix-run/router@0.0.0-experimental-0db28b07 (3/24/2023, 3:35:26 PM) | @remix-run/router@1.5.0-pre.2 (3/24/2023, 3:30:37 PM) | package.json via react-router-dom@6.10.0 |
| path-to-regexp@1.8.0 (upgraded) | path-to-regexp@3.1.0 (8/31/2019, 3:59:25 AM) | path-to-regexp@1.7.0 (11/8/2016, 6:38:49 PM) | package.json via react-router-transition@1.3.0 |
| react-router@6.10.0 (upgraded) | react-router@0.0.0-experimental-0db28b07 (3/24/2023, 3:35:28 PM) | react-router@6.10.0-pre.2 (3/24/2023, 3:30:36 PM) | package.json via react-router-dom@6.10.0 |
| react-router-dom@6.10.0 (upgraded) | react-router-dom@0.0.0-experimental-0db28b07 (3/24/2023, 3:35:30 PM) | react-router-dom@6.10.0-pre.2 (3/24/2023, 3:30:36 PM) | package.json |
⚠️ Unmaintained
Package has not been updated in more than a year and may be unmaintained. Problems with the package may go unaddressed.
Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
| Package | Last Publish Date | Source |
|---|---|---|
| css-select@1.2.0 (added) | 4/27/2022, 6:29:37 PM | package.json via react-scripts@3.0.1 |
| css-select@2.0.2 (added) | 4/27/2022, 6:29:37 PM | package.json via react-scripts@3.0.1 |
Pull request alert summary
📊 Modified Dependency Overview:
| ⬆️ Updated Package | Version Diff | Added Capability Access | +/- Transitive Count |
Publisher |
|---|---|---|---|---|
| react-router-dom@6.10.0 | 5.0.1...6.10.0 | network | +2/-9 |
mjackson |
|
Superseded by #170. |
Bumps react-router-dom from 5.0.1 to 6.10.0.
Release notes
Sourced from react-router-dom's releases.
... (truncated)
Changelog
Sourced from react-router-dom's changelog.
... (truncated)
Commits
a3927fechore: Update version for release (#10284)8f7939cchore: Update version for release (pre) (#10260)7799f6cchore: Update version for release (pre) (#10248)97b5c42chore: Update version for release (pre) (#10243)dff7e64Add future.v7_normalizeFormMethod flag (#10207)6c68e1eProperly handle lazy errors during router initialization (#10201)474feb7Remove wrapper API from data browser router tests (#10196)7ba352echore: format0f561eefix(react-router-dom): fixdetectErrorBoundaryfunction (#10190)4ec107achore: Update version for release (#10185)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)