Context
Advisory GHSA-qwww-vcr4-c8h2 — React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response — published 2026-07-25, severity high, vulnerable range react-router 7.12.0–8.2.0. Our SPA resolves react-router@7.18.1 via react-router-dom@^7.1.1, so the F146 npm vuln gate (#146) now blocks every PR's "Web typecheck, test, and build" job.
Why an exception instead of a bump
- The only patched release is 8.3.0 — a semver-major migration (
npm audit fix is a no-op; only --force would take it).
- The
version-7 dist-tag still points at 7.18.1: no 7.x backport exists yet.
- The vulnerable code path is RSC mode (server actions). The SPA uses classic
BrowserRouter client-side routing only — no RSC, no server actions — so the advisory is not reachable in Cluckwork.
Per the .github/security-exceptions.json policy (breaking-major fix → file the tracking PR/issue and link it), a temporary exception was added, expiring 2026-08-24.
Done means
Either:
Remove the entry from .github/security-exceptions.json in the same PR. If neither lands before 2026-08-24, the gate re-blocks and the exception must be consciously re-evaluated, not blindly extended.
Epic: #15
Context
Advisory GHSA-qwww-vcr4-c8h2 — React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response — published 2026-07-25, severity high, vulnerable range
react-router7.12.0–8.2.0. Our SPA resolvesreact-router@7.18.1viareact-router-dom@^7.1.1, so the F146 npm vuln gate (#146) now blocks every PR's "Web typecheck, test, and build" job.Why an exception instead of a bump
npm audit fixis a no-op; only--forcewould take it).version-7dist-tag still points at 7.18.1: no 7.x backport exists yet.BrowserRouterclient-side routing only — no RSC, no server actions — so the advisory is not reachable in Cluckwork.Per the
.github/security-exceptions.jsonpolicy (breaking-major fix → file the tracking PR/issue and link it), a temporary exception was added, expiring 2026-08-24.Done means
Either:
web/to react-router 8.x → remove the exceptionRemove the entry from
.github/security-exceptions.jsonin the same PR. If neither lands before 2026-08-24, the gate re-blocks and the exception must be consciously re-evaluated, not blindly extended.Epic: #15