Skip to content

Update React to 19.2.3 for CVE fixes#423

Merged
heyitsaamir merged 2 commits into
mainfrom
copilot/update-react-to-1922
Jan 15, 2026
Merged

Update React to 19.2.3 for CVE fixes#423
heyitsaamir merged 2 commits into
mainfrom
copilot/update-react-to-1922

Conversation

Copilot AI commented Dec 11, 2025

Copy link
Copy Markdown
Contributor

Addresses DoS and source code exposure vulnerabilities in React Server Components (advisory).

Changes

  • Bump React and React DOM from ^19.2.1 to ^19.2.2 in:
    • examples/tab/package.json
    • packages/devtools/package.json
  • npm resolved to 19.2.3 (latest patch satisfying constraint)

Notes

Only two workspaces use React. No code changes required—dependency version bump only.

Original prompt

We need to update to react 19.2.2 (and also react dom). Follow patterns in #419. This is because of vulnerabilities listed in https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components

skip-test-verification


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Copilot AI changed the title [WIP] Update React and React DOM to version 19.2.2 Update React to 19.2.3 for CVE fixes Dec 11, 2025
Copilot AI requested a review from heyitsaamir December 11, 2025 23:24
@heyitsaamir
heyitsaamir marked this pull request as ready for review December 12, 2025 00:20
@heyitsaamir
heyitsaamir merged commit a2858fc into main Jan 15, 2026
10 of 15 checks passed
@heyitsaamir
heyitsaamir deleted the copilot/update-react-to-1922 branch January 15, 2026 05:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants