Skip to content

[Cycode] Fix for vulnerable manifest file dependency - react-router-dom updated to version 6.30.4#85

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-da4497f6-30bc-4c50-8f6b-80e8ced1ac00
Open

[Cycode] Fix for vulnerable manifest file dependency - react-router-dom updated to version 6.30.4#85
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-da4497f6-30bc-4c50-8f6b-80e8ced1ac00

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Jun 4, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
ui/app/package.json 1

📂 ui/app/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
react-router-dom 6.30.1 6.30.4

Warning

Lock file generation failed for one or more manifest files in this pull request. Please regenerate the lock file manually before merging.


Note

Low Risk
Single patch-level dependency bump with no routing logic changes; ensure the lockfile is updated before merge.

Overview
Bumps react-router-dom in ui/app/package.json from ^6.30.1 to ^6.30.4 to address reported vulnerable dependency findings. There are no application source changes in this diff—only the declared dependency version.

Before merge: regenerate the app lockfile (the PR notes lockfile generation failed) so installs resolve to the patched release consistently.

Reviewed by Cursor Bugbot for commit b65c16e. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants