Commit 4ef0cba
committed
fix(security): upgrade Remix packages 2.1.0 → 2.17.3
Addresses CVE-2026-22029 (XSS via open redirects in loaders/actions).
Upgraded packages:
- @remix-run/express: 2.1.0 → 2.17.3
- @remix-run/node: 2.1.0 → 2.17.3
- @remix-run/react: 2.1.0 → 2.17.3
- @remix-run/router: 1.15.3 → 1.23.2
- @remix-run/serve: 2.1.0 → 2.17.3
- @remix-run/server-runtime: 2.1.0 → 2.17.3
- @remix-run/dev: 2.1.0 → 2.17.3
- @remix-run/eslint-config: 2.1.0 → 2.17.3
- @remix-run/testing: 2.1.0 → 2.17.3
Also updated tar-fs override for new @remix-run/dev version.1 parent eeab6bd commit 4ef0cba
3 files changed
+443
-399
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
100 | 100 | | |
101 | 101 | | |
102 | 102 | | |
103 | | - | |
104 | | - | |
105 | | - | |
106 | | - | |
107 | | - | |
108 | | - | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
109 | 109 | | |
110 | 110 | | |
111 | 111 | | |
| |||
228 | 228 | | |
229 | 229 | | |
230 | 230 | | |
231 | | - | |
232 | | - | |
233 | | - | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
234 | 234 | | |
235 | 235 | | |
236 | 236 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | | - | |
| 89 | + | |
90 | 90 | | |
91 | 91 | | |
92 | 92 | | |
| |||
0 commit comments