Skip to content

Unconditional version-check fetch to react-grab.com on start() with no opt-out #472

Description

@pranaysuyash

Summary

packages/scan/src/web/utils/check-react-grab-version.ts:14-37 (called from packages/scan/src/core/index.ts:470) fetches:

https://www.react-grab.com/api/version?source=react-scan&v=<bundled version>&t=<Date.now()>

on every start(). This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is no opt-out flag.

Mitigating factors

  • start() early-returns in production builds (core/index.ts:462-468) unless dangerouslyForceRunInProduction, so this mainly fires in dev.
  • Payload is minimal (version + timestamp), but IP/UA are inherent to any HTTP request.

Suggested fix

  1. Gate behind the same telemetry/DO_NOT_TRACK conventions used elsewhere in the ecosystem (react-grab CLI honors DO_NOT_TRACK; react-doctor has --no-telemetry).
  2. Document the ping in the README regardless.

Note: react-scan/lite already does this exactly right — event POSTing is strictly opt-in, and lite.test.ts:83-84 asserts lite never touches fetch/XHR. Applying the same philosophy to the version check would make the package consistent.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions