Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 8, 2026

This PR contains the following updates:

Package Change Age Confidence
@remix-run/react (source) 2.16.62.17.3 age confidence

GitHub Vulnerability Alerts

CVE-2025-59057

A XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.

Note

This does not impact applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).

CVE-2026-21884

A XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys.

Note

This does not impact applications if developers have disabled server-side rendering in Framework Mode, or if they are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).


Release Notes

remix-run/remix (@​remix-run/react)

v2.17.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added dependencies Pull requests that update a dependency file javascript labels Jan 8, 2026
@renovate renovate bot requested a review from a team as a code owner January 8, 2026 20:53
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Jan 8, 2026
@renovate renovate bot enabled auto-merge (squash) January 8, 2026 20:53
@renovate renovate bot added the javascript label Jan 8, 2026
@netlify
Copy link

netlify bot commented Jan 8, 2026

Deploy Preview for remix-edge failed. Why did it fail? →

Name Link
🔨 Latest commit fcdf9ae
🔍 Latest deploy log https://app.netlify.com/projects/remix-edge/deploys/696e61d54942a9000813e290

@netlify
Copy link

netlify bot commented Jan 8, 2026

Deploy Preview for remix-serverless failed. Why did it fail? →

Name Link
🔨 Latest commit fcdf9ae
🔍 Latest deploy log https://app.netlify.com/projects/remix-serverless/deploys/696e61d5baca5000077d3ebe

@github-actions github-actions bot added the type: chore work needed to keep the product and development running smoothly label Jan 8, 2026
kodiakhq[bot]
kodiakhq bot previously approved these changes Jan 8, 2026
@renovate renovate bot force-pushed the renovate/npm-remix-run-react-vulnerability branch from 1c2c671 to 50a92d6 Compare January 8, 2026 21:07
@renovate renovate bot changed the title chore(deps): update dependency @remix-run/react to v2.17.1 [security] chore(deps): update dependency @remix-run/react to v2.17.3 [security] Jan 8, 2026
@renovate renovate bot force-pushed the renovate/npm-remix-run-react-vulnerability branch from 50a92d6 to fcdf9ae Compare January 19, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript type: chore work needed to keep the product and development running smoothly

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant