chore(deps): bump react-router from 7.18.0 to 8.3.0 - #20927
chore(deps): bump react-router from 7.18.0 to 8.3.0#20927dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) from 7.18.0 to 8.3.0. - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/react-router@8.3.0/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 8.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Reviewing this major version bump. Workflow run |
|
|
BLEnder picked up this PR. Workflow run |
…einstall check The preinstall hook runs _scripts/check-node-version.sh, which read the pinned version from .nvmrc (24.15.0) and passed it to semver.satisfies as a validRange. A bare version string is a valid range that matches only that exact version, so CI's Node 24.18.0 was rejected with INCOMPATIBLE NODE VERSION, aborting the build before any package work ran. This contradicted package.json engines (^24.15.0) and the script's own no-semver fallback, which only checks the major version. Changed the semver comparison to treat the required version as a caret range (^24.15.0) so any compatible 24.x >= 24.15.0 runtime passes.
|
NO_VERDICT: could not evaluate this major version bump — manual review needed. |
|
Reviewing this major version bump. Workflow run |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
|
BLEnder investigated: This dependency has an open security alert, but the repo is not affected.
This PR can be reviewed and merged as a normal dependency update. |
Bumps react-router from 7.18.0 to 8.3.0.
Release notes
Sourced from react-router's releases.
Changelog
Sourced from react-router's changelog.
... (truncated)
Commits
2edaca7Release v8.3.0 (#15294)687ab72Prep release notesd2f1f1bupdate changes files to use h4 instead of h3 (#15334)8186207fix(rsc): preserve component metadata for client loader revalidation (#15323)c26e431feat(rsc): support CSP nonces in document rendering (#15320)6286f90feat(rsc): reload stale clients after new deployments (#15318)3d83ad4docs: fix useLinkClickHandler defaultShouldRevalidate default description (#1...f75c89fUpdate docs links to v8 API reference (#15316)baa9ba6fix: encode path params per RFC 3986 path-segment rules in href/generatePath ...69debd1fix: apply NavLink pending state when the to prop has a trailing slash (#15300)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.