Skip to content

GHSA-qwww-vcr4-c8h2 affected range appears outdated #9018

Description

@TrendPivot

react-router@7.18.2 includes the backported fix for GHSA-qwww-vcr4-c8h2, but npm audit still reports it as vulnerable because the advisory currently lists the affected range as >=7.12.0 <8.2.0.

The fix was backported to the 7.x release line and shipped in 7.18.2. Could the affected version range be updated to exclude 7.18.2 (or whatever the correct fixed boundary is)?

This currently results in a false positive from npm audit.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions