Skip to content

[Cycode] Fix for vulnerable manifest file dependency - react-router-dom updated to version 6.30.4#86

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-438a7adc-0533-41e4-b3f4-883f072970ec
Open

[Cycode] Fix for vulnerable manifest file dependency - react-router-dom updated to version 6.30.4#86
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-438a7adc-0533-41e4-b3f4-883f072970ec

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Jun 4, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
ui/explore/package.json 1

📂 ui/explore/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
react-router-dom 6.30.1 6.30.4

Warning

Lock file generation failed for one or more manifest files in this pull request. Please regenerate the lock file manually before merging.


Note

Low Risk
Patch-level devDependency bump with no runtime code changes; main merge risk is an out-of-date lockfile if installs are lock-driven.

Overview
Bumps the react-router-dom devDependency in ui/explore/package.json from ^6.30.1 to ^6.30.4 to address a reported vulnerable dependency. There are no application or library source changes in this diff—only the manifest version range.

Reviewers should regenerate the explore package lockfile before merge if your workflow requires it; the PR notes lock generation did not run automatically.

Reviewed by Cursor Bugbot for commit 396a127. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants