Repository navigation
fix: bump react-router-dom to ^7.18.0 in web-extension (dependency vulnerabilities) - #41
Open
devin-ai-integration[bot] wants to merge 1 commit into
Conversation
…endency vulnerabilities Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Contributor
Author
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependency vulnerability fixes (automated)
Generated by the Devin Dependency Security Vuln Fix automation run on 2026-10-05.
Change type: Major version bump — includes source/config changes to adapt to a breaking change.
Warning
We're not just looking for a review like a normal PR. Security can offer this fix as a recommendation, but doesn't have the tooling or domain knowledge to safely verify changes like this end-to-end for each repo. Please review, test, and own deployment before merging. For more information: https://launchdarkly.atlassian.net/wiki/spaces/SEC/pages/5360943572/Dependency+Vulnerability+Remediation+with+Devin.
Findings addressed
packages/web-extension, viareact-router-dom)react-router-dom ^6.4.1) → 7.18.4 (react-router-dom ^7.18.0)Notes for reviewers:
react-router >= 6.x, < 7.18.0with no 6.x backport, so the 7.x major is the only fix. GHSA-wrjc-x8rr-h8h6 (open redirect via backslash in<Link>/useNavigate) applies to client-side routing, which the extension uses. GHSA-337j-9hxr-rhxg only affects SSR hydration, which the extension doesn't do.packages/web-extension/package.json.createHashRouter,RouterProvider,Routes,Route,useNavigateanduseParamsfromreact-router-dom, and all of them still exist in v7.react-router-dom7 re-exportsreact-router, so no import changes were needed.navigate()returnsvoid | Promise<void>, which makes@typescript-eslint/no-floating-promisesfail atpackages/web-extension/src/pages/SessionList.tsx. The call is now prefixed withvoid, so runtime behavior doesn't change.web-extensionis a private app package with no exported API, so this PR isfix:and notfix!:.packages/web-extension/package.jsonbut a different line, so there's no conflict.Deferred / excluded findings
packages/rrweb-player) ^4.2.14 → 5.55.7, Medium, 227d (Dependabot #52–#55, #75, #76). Fully fixed by Dependabot chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates #32 (^5.56.3), which has green CI.Verification
yarn installresolvesreact-router/react-router-dom7.18.4. The only install failure ispackages/rrvideo's Playwright browser postinstall, which can't reach the Playwright CDN from the automation sandbox. This happens onmaintoo.yarn build:allpasses 22/22, including the chrome and firefox builds ofweb-extension. Locally,web-extension's manifest schema validation had to be skipped because the sandbox can't fetch the schema. CI runs the full validation.web-extensionhas no test suite, and no other package changed. The full browser test suite runs in CI.yarn linthas no new errors. The only errors are the same 3rrweb-player.svelteparser errors as onmain. Without thevoidchange, v7 adds a 4th error (no-floating-promises).yarn check-typespasses 34/34 and Prettier is clean.Link to Devin session: https://app.devin.ai/sessions/f0e11a0113ee4897821aa7d14857174d
Open in Devin Desktop: https://app.devin.ai/desktop/session/f0e11a0113ee4897821aa7d14857174d?variant=devin
Note
Overview
Upgrades
react-router-domin the web extension from v6 to ^7.18.0 to address medium-severity routing advisories (including client-side open-redirect issues) where no patched 6.x release exists.The only code adaptation is prefixing the session table row
navigate()call withvoidinSessionList.tsx, because v7 typesnavigateas possibly returning a promise and the existing lint rule flags an unhandled promise; behavior is unchanged.Reviewed by Cursor Bugbot for commit e5de2d0. Bugbot is set up for automated code reviews on this repo. Configure here.