security(frontend): bump react-router-dom to 7.18.1 for patched release

Moves react-router-dom/react-router 7.16.0 -> 7.18.1, off the range
flagged by GHSA-wrjc-x8rr-h8h6 (open redirect via backslash in Link/
useNavigate), GHSA-h8fp-f39c-q6mh (RSC), and GHSA-337j-9hxr-rhxg (SSR
hydration). The latter two need RSC/SSR, neither of which this
client-only SPA uses; the open-redirect one is the only reachable path
(post-login redirect), already guarded by sanitizeRedirectTarget.

Stays within the existing ^7.16.0 caret, no new transitive deps. Rebuilt
the static bundle. npm audit now reports 0 vulnerabilities.
This commit is contained in:
maziggy
2026-07-24 10:55:55 +02:00
parent 83ac5b361c
commit a273cd3eec
3 changed files with 146 additions and 149 deletions
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -26,7 +26,7 @@
<!-- Splash screens for iOS -->
<link rel="apple-touch-startup-image" href="/img/android-chrome-512x512.png" />
<script type="module" crossorigin src="/assets/index-DMXg01ou.js"></script>
<script type="module" crossorigin src="/assets/index-ByvLwk1T.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-kl51qImb.css">
</head>
<body>