Skip to content

build(deps): bump react-router from 7.18.0 to 7.18.2 in /client in the npm_and_yarn group across 1 directory - #6971

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/client/npm_and_yarn-aa586a9240
Open

build(deps): bump react-router from 7.18.0 to 7.18.2 in /client in the npm_and_yarn group across 1 directory#6971
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/client/npm_and_yarn-aa586a9240

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /client directory: react-router.

Updates react-router from 7.18.0 to 7.18.2

Release notes

Sourced from react-router's releases.

v7.18.2

See the changelog for release notes: https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7182

v7.18.1

See the changelog for release notes: https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7181

Changelog

Sourced from react-router's changelog.

v7.18.2

Patch Changes

  • Harden RSC CSRF codepaths. (#15353)

v7.18.1

Patch Changes

  • No changes
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 3, 2026
@dependabot
dependabot Bot requested a review from matthewevans as a code owner August 3, 2026 17:45

@matthewevans matthewevans left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested

This PR changes the protected frontend dependency manifest, moving react-router from 7.18.0 to 8.3.0. Major dependency upgrades require explicit maintainer review of the migration and runtime compatibility before they can be accepted; CI success alone is not sufficient evidence for this supply-chain surface.

No implementation review or approval is being given on this automated update. Please route the upgrade through the project’s dependency-maintenance process with the required compatibility assessment.

@matthewevans matthewevans added the enhancement New feature or request label Aug 3, 2026
Bumps the npm_and_yarn group with 1 update in the /client directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router).


Updates `react-router` from 7.18.0 to 7.18.2
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router@7.18.2/packages/react-router/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router@7.18.2/packages/react-router)

---
updated-dependencies:
- dependency-name: react-router
  dependency-version: 8.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump react-router from 7.18.0 to 8.3.0 in /client in the npm_and_yarn group across 1 directory build(deps): bump react-router from 7.18.0 to 7.18.2 in /client in the npm_and_yarn group across 1 directory Aug 21, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/client/npm_and_yarn-aa586a9240 branch from b2338b7 to 66a42c2 Compare August 21, 2026 17:48
@matthewevans matthewevans self-assigned this Aug 21, 2026

@matthewevans matthewevans left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — protected dependency manifest on current head 66a42c219561d0b1eaf04fb881cac84b323c5ff6

This PR modifies the hard-stop path client/package.json:38, changing react-router from ^7.18.0 to ^7.18.2, and refreshes the corresponding lockfile graph in client/pnpm-lock.yaml. Under .agents/pr-review-policy.toml's hard_stops policy, that protected dependency-manifest change requires the project's dependency-maintenance compatibility assessment before approval; passing CI and supply-chain scan are not that assessment.

No implementation review or approval is given for this automated update. Please route the current-head update through the dependency-maintenance process with explicit runtime/migration compatibility evidence, then request a new review.

@matthewevans matthewevans removed their assignment Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file enhancement New feature or request javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant