Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 11, 2026

This PR contains the following updates:

Package Change Age Confidence
@remix-run/react (source) 2.16.42.17.3 age confidence

GitHub Vulnerability Alerts

CVE-2025-59057

A XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.

Note

This does not impact applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).

CVE-2026-21884

A XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys.

Note

This does not impact applications if developers have disabled server-side rendering in Framework Mode, or if they are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).


Release Notes

remix-run/remix (@​remix-run/react)

v2.17.0

Compare Source

v2.16.5

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency label Jan 11, 2026
@netlify
Copy link

netlify bot commented Jan 11, 2026

Deploy Preview for brilliant-pasca-3e80ec canceled.

Name Link
🔨 Latest commit eb8d50e
🔍 Latest deploy log https://app.netlify.com/projects/brilliant-pasca-3e80ec/deploys/6978f4d123d6a9000709d731

@renovate renovate bot force-pushed the renovate-npm-remix-run-react-vulnerability branch from d009780 to f48c33d Compare January 20, 2026 20:02
@github-actions
Copy link

github-actions bot commented Jan 20, 2026

🚀 Performance Test Results

Test Configuration:

  • VUs: 4
  • Duration: 1m0s

Test Metrics:

  • Requests/s: 40.76
  • Iterations/s: 13.60
  • Failed Requests: 0.00% (0 of 2454)
📜 Logs

> [email protected] run-tests:testenv /home/runner/work/rafiki/rafiki/test/performance
> ./scripts/run-tests.sh -e test "-k" "-q" "--vus" "4" "--duration" "1m"

Cloud Nine GraphQL API is up: http://localhost:3101/graphql
Cloud Nine Wallet Address is up: http://localhost:3100/
Happy Life Bank Address is up: http://localhost:4100/
cloud-nine-wallet-test-backend already set
cloud-nine-wallet-test-auth already set
happy-life-bank-test-backend already set
happy-life-bank-test-auth already set
     data_received..................: 886 kB 15 kB/s
     data_sent......................: 1.9 MB 31 kB/s
     http_req_blocked...............: avg=6.86µs   min=2.54µs   med=5.31µs   max=484.67µs p(90)=6.47µs   p(95)=7.08µs  
     http_req_connecting............: avg=327ns    min=0s       med=0s       max=289.41µs p(90)=0s       p(95)=0s      
     http_req_duration..............: avg=97.47ms  min=6.71ms   med=78.13ms  max=695.67ms p(90)=171.08ms p(95)=191.96ms
       { expected_response:true }...: avg=97.47ms  min=6.71ms   med=78.13ms  max=695.67ms p(90)=171.08ms p(95)=191.96ms
     http_req_failed................: 0.00%  ✓ 0         ✗ 2454
     http_req_receiving.............: avg=91.38µs  min=31.37µs  med=80.07µs  max=2.39ms   p(90)=116.46µs p(95)=147.66µs
     http_req_sending...............: avg=36.74µs  min=11.44µs  med=27.58µs  max=1.73ms   p(90)=40.5µs   p(95)=53.68µs 
     http_req_tls_handshaking.......: avg=0s       min=0s       med=0s       max=0s       p(90)=0s       p(95)=0s      
     http_req_waiting...............: avg=97.34ms  min=6.54ms   med=78.01ms  max=695.58ms p(90)=170.99ms p(95)=191.83ms
     http_reqs......................: 2454   40.756631/s
     iteration_duration.............: avg=293.76ms min=173.81ms med=279.89ms max=1.16s    p(90)=345.53ms p(95)=401.72ms
     iterations.....................: 819    13.602152/s
     vus............................: 4      min=4       max=4 
     vus_max........................: 4      min=4       max=4 

@renovate renovate bot force-pushed the renovate-npm-remix-run-react-vulnerability branch 4 times, most recently from cdbdf75 to 3756b2b Compare January 27, 2026 17:24
@renovate renovate bot force-pushed the renovate-npm-remix-run-react-vulnerability branch from 3756b2b to eb8d50e Compare January 27, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants