Skip to content

Conversation

@haakonmb
Copy link

@haakonmb haakonmb commented Dec 4, 2025

ref https://vercel.com/changelog/cve-2025-55182

This PR upgrades the versions of react and react-dom to 19.2.1 to avoid this vulnerability propagating downstream.

The patch-bump shouldnt have any functional changes other than fixing the vulnerability, but it bears mentioning that I havent tested this in detail for this repository.

This is mainly me making available a change I was deploying for other projects I'm responsible for, and I noticed this library potentially propagating this vulnerability downstream. Hopefully this is useful for you in some manner!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant