Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/ui/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@
"react-hotkeys": "^2.0.0",
"react-monaco-editor": "^0.36.0",
"react-resizable": "^1.10.1",
"react-router": "^5.2.0",
"react-router": "^7.5.2",
"react-router-dom": "^5.2.0",
"react-split": "^2.0.7",
"react-table": "^7.7.0",
Expand Down
42 changes: 40 additions & 2 deletions src/ui/yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -2842,7 +2842,7 @@
react-hotkeys: ^2.0.0
react-monaco-editor: ^0.36.0
react-resizable: ^1.10.1
react-router: ^5.2.0
react-router: ^7.5.2
react-router-dom: ^5.2.0
react-split: ^2.0.7
react-table: ^7.7.0
Expand Down Expand Up @@ -5843,6 +5843,13 @@
languageName: node
linkType: hard

"cookie@npm:^1.0.1":
version: 1.0.2
resolution: "cookie@npm:1.0.2"
checksum: 2c5a6214147ffa7135ce41860c781de17e93128689b0d080d3116468274b3593b607bcd462ac210d3a61f081db3d3b09ae106e18d60b1f529580e95cf2db8a55
languageName: node
linkType: hard

"copy-descriptor@npm:^0.1.0":
version: 0.1.1
resolution: "copy-descriptor@npm:0.1.1"
Expand Down Expand Up @@ -12974,26 +12981,43 @@
languageName: node
linkType: hard

"react-router@npm:5.2.0, react-router@npm:^5.2.0":
"react-router@npm:5.2.0":
version: 5.2.0
resolution: "react-router@npm:5.2.0"
dependencies:
"@babel/runtime": ^7.1.2
history: ^4.9.0
hoist-non-react-statics: ^3.1.0
loose-envify: ^1.3.1
mini-create-react-context: ^0.4.0
path-to-regexp: ^1.7.0
prop-types: ^15.6.2
react-is: ^16.6.0
tiny-invariant: ^1.0.2
tiny-warning: ^1.0.0
peerDependencies:
react: ">=15"
checksum: 6fc908729110a65a5676a9e41333e0f511a3c0ff84c93c0dc704330cf3e02124c93aaeab8031b0e2c71712390d9278fff848eeebfbdda36dca3201142f309973
languageName: node
linkType: hard

Check failure

Code scanning / trivy-fs

React Router allows pre-render data spoofing on React-Router framework mode High

Package: react-router
Installed Version: 5.2.0
Vulnerability GHSA-cpj6-fhp6-mr6j
Severity: HIGH
Fixed Version: 7.5.2
Link: GHSA-cpj6-fhp6-mr6j

Check failure

Code scanning / trivy-fs

React Router allows a DoS via cache poisoning by forcing SPA mode High

Package: react-router
Installed Version: 5.2.0
Vulnerability GHSA-f46r-rw29-r322
Severity: HIGH
Fixed Version: 7.5.2
Link: GHSA-f46r-rw29-r322

"react-router@npm:^7.5.2":
version: 7.5.2
resolution: "react-router@npm:7.5.2"
dependencies:
cookie: ^1.0.1
set-cookie-parser: ^2.6.0
turbo-stream: 2.4.0
peerDependencies:
react: ">=18"
react-dom: ">=18"
peerDependenciesMeta:
react-dom:
optional: true
checksum: cc8c9729c4adc79c82ab9435594dffcdf0659d555d5da0f6f530d4e8d19f1c0bcd08f1b4fc8df8ca6ce021b6fa3da87f01498f55b36b1821a5c8da3bb69955a0
languageName: node
linkType: hard

"react-split@npm:^2.0.7":
version: 2.0.10
resolution: "react-split@npm:2.0.10"
Expand Down Expand Up @@ -13798,6 +13822,13 @@
languageName: node
linkType: hard

"set-cookie-parser@npm:^2.6.0":
version: 2.7.1
resolution: "set-cookie-parser@npm:2.7.1"
checksum: 2ef8b351094712f8f7df6d63ed4b10350b24a5b515772690e7dec227df85fcef5bc451c7765f484fd9f36694ece5438d1456407d017f237d0d3351d7dbbd3587
languageName: node
linkType: hard

"set-value@npm:^2.0.0, set-value@npm:^2.0.1":
version: 2.0.1
resolution: "set-value@npm:2.0.1"
Expand Down Expand Up @@ -15105,6 +15136,13 @@
languageName: node
linkType: hard

"turbo-stream@npm:2.4.0":
version: 2.4.0
resolution: "turbo-stream@npm:2.4.0"
checksum: e36f52ed40589f01bede79757a143bef484914d579927235be1fd0c205618994cb5779a39ff8c2a80a87a1464d05771cd75320a9412b15bca03c7ff432e3cdf7
languageName: node
linkType: hard

"tweetnacl@npm:^0.14.3, tweetnacl@npm:~0.14.0":
version: 0.14.5
resolution: "tweetnacl@npm:0.14.5"
Expand Down
Loading