Fix server handler prerender responses when using ssr: false and future.v8_trailingSlashAwareDataRequests: true. Avoids false positive "SPA Mode" detection when serving prerendered paths (#15173)
Use the ServerRouter nonce for nonce-aware SSR components when they don't provide their own value so strict CSP pages can load them. (#15170)
Use turbo-stream to serialize and deserialize Framework Mode hydration errors (#15175)
Precompute route branch matchers to avoid recompiling route path regexes during matching (#15186)
Use the constructed request URL host when validating action request origins. (#15185)
Remove the un-documented custom error serialization logic from Data Mode SSR built-in hydration flows (#15175)
Validate protocols in RSC render redirects (#15177)
Consolidate url normalization logic and better handle mixed slashes (#15176)
v7.17.0
Minor Changes
Ship a subset of the official documentation inside the react-router package (#15121)
Markdown docs are now available in node_modules/react-router/docs, letting AI coding agents and the React Router agent skills read official docs locally
Excludes auto-generated API docs (api/), community/ content, and tutorials (tutorials/)
Remove stale/invalid unpkg field from package.json. This was removed from other packages with the release of v7 but missed in the react-router-dom re-export package (#15075)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Bumps [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) to 7.18.4 and updates ancestor dependency [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom). These dependencies need to be updated together.
Updates `react-router` from 6.30.4 to 7.18.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/remix-run/react-router/releases">react-router's releases</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7184">https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7184</a></p>
<h2>v7.18.3</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7183">https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7183</a></p>
<h2>v7.18.2</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7182">https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7182</a></p>
<h2>v7.18.1</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7181">https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7181</a></p>
<h2>v7.18.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180</a></p>
<h2>v7.17.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7170">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7170</a></p>
<h2>v7.16.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7160">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7160</a></p>
<h2>v7.15.1</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7151">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7151</a></p>
<h2>v7.15.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7150">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7150</a></p>
<h2>v7.14.2</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7142">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7142</a></p>
<h2>v7.14.1</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7141">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7141</a></p>
<h2>v7.14.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7140">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7140</a></p>
<h2>v7.13.2</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7132">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7132</a></p>
<h2>v7.13.1</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7131">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7131</a></p>
<h2>v7.13.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7130">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7130</a></p>
<h2>v7.12.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7120">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7120</a></p>
<h2>v7.11.0</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7110">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7110</a></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/remix-run/react-router/blob/[email protected]/packages/react-router/CHANGELOG.md">react-router's changelog</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Correctly escape streamed RSC redirect locations in meta tag attributes (<a href="https://redirect.github.com/remix-run/react-router/pull/15492">#15492</a>)</li>
<li>Avoid unintended <code>document.startViewTransition</code> calls during initial hydration and <code>router.revalidate()</code> calls (<a href="https://redirect.github.com/remix-run/react-router/pull/15485">#15485</a>)</li>
</ul>
<h2>v7.18.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Improve route matching performance for long paths (<a href="https://redirect.github.com/remix-run/react-router/pull/15423">#15423</a>)</li>
<li>Improve validation of action request origins (<a href="https://redirect.github.com/remix-run/react-router/pull/15420">#15420</a>)</li>
<li>Add additional URL validation on client side navigations/redirects (<a href="https://redirect.github.com/remix-run/react-router/pull/15446">#15446</a>)</li>
</ul>
<h2>v7.18.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Harden RSC CSRF codepaths. (<a href="https://redirect.github.com/remix-run/react-router/pull/15353">#15353</a>)</li>
</ul>
<h2>v7.18.1</h2>
<h3>Patch Changes</h3>
<ul>
<li><em>No changes</em></li>
</ul>
<h2>v7.18.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Fix server handler prerender responses when using <code>ssr: false</code> and <code>future.v8_trailingSlashAwareDataRequests: true</code>. Avoids false positive "SPA Mode" detection when serving prerendered paths (<a href="https://redirect.github.com/remix-run/react-router/pull/15173">#15173</a>)</li>
<li>Use the <code>ServerRouter</code> nonce for nonce-aware SSR components when they don't provide their own value so strict CSP pages can load them. (<a href="https://redirect.github.com/remix-run/react-router/pull/15170">#15170</a>)</li>
<li>Use <code>turbo-stream</code> to serialize and deserialize Framework Mode hydration errors (<a href="https://redirect.github.com/remix-run/react-router/pull/15175">#15175</a>)</li>
<li>Precompute route branch matchers to avoid recompiling route path regexes during matching (<a href="https://redirect.github.com/remix-run/react-router/pull/15186">#15186</a>)</li>
<li>Use the constructed request URL host when validating action request origins. (<a href="https://redirect.github.com/remix-run/react-router/pull/15185">#15185</a>)</li>
<li>Remove the un-documented custom error serialization logic from Data Mode SSR built-in hydration flows (<a href="https://redirect.github.com/remix-run/react-router/pull/15175">#15175</a>)</li>
<li>Validate protocols in RSC render redirects (<a href="https://redirect.github.com/remix-run/react-router/pull/15177">#15177</a>)</li>
<li>Consolidate url normalization logic and better handle mixed slashes (<a href="https://redirect.github.com/remix-run/react-router/pull/15176">#15176</a>)</li>
</ul>
<h2>v7.17.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>Ship a subset of the official documentation inside the <code>react-router</code> package (<a href="https://redirect.github.com/remix-run/react-router/pull/15121">#15121</a>)
<ul>
<li>Markdown docs are now available in <code>node_modules/react-router/docs</code>, letting AI coding agents and the React Router agent skills read official docs locally</li>
<li>Excludes auto-generated API docs (<code>api/</code>), <code>community/</code> content, and tutorials (<code>tutorials/</code>)</li>
</ul>
</li>
</ul>
<h2>v7.16.0</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a> Release v7.18.4 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15498">#15498</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/3e4d295d0cef27cad3f754f173eaeeec5aec5986"><code>3e4d295</code></a> [v7] Skip view transitions on revalidation and initial hydration (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15485">#15485</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/e0c6b5bce96f249a71b1fc395000c6b2742c57d7"><code>e0c6b5b</code></a> Fix HTML attribute escaping for RSC redirects (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15492">#15492</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a> Release v7.18.3 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15424">#15424</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/38af67f5cada15f0f540c597929a1b08022b46a5"><code>38af67f</code></a> Validate client-side navigation targets (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15446">#15446</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/df78a297667c8891de29615f364a837ff858d45f"><code>df78a29</code></a> Revert "fix: normalize control characters in relative URLs (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15422">#15422</a>)" (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15441">#15441</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/d1a4b1d4ad9e230fbe2653b60fed20dff6872f60"><code>d1a4b1d</code></a> fix: normalize control characters in relative URLs (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15422">#15422</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/e7c2d94ca41e8c8d1312a3e004d6f88b252509db"><code>e7c2d94</code></a> Revert "fix: normalize RSC server redirects (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15421">#15421</a>)" (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15434">#15434</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/e4b70d65d0188846baf0f1dad4bb05f6781186ea"><code>e4b70d6</code></a> fix: validate schemeful action origins (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15420">#15420</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/b137cabaeb92b15b97233e75e0afa09f70307e84"><code>b137cab</code></a> fix: normalize RSC server redirects (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15421">#15421</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router">compare view</a></li>
</ul>
</details>
<br />
Updates `react-router-dom` from 6.30.4 to 7.18.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/remix-run/react-router/releases">react-router-dom's releases</a>.</em></p>
<blockquote>
<h2>v7.1.3</h2>
<p>See the changelog for release notes: <a href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v713">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v713</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/remix-run/react-router/blob/[email protected]/packages/react-router-dom/CHANGELOG.md">react-router-dom's changelog</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Fix incorrect <code>package.json</code> <code>main</code> field for CommonJS builds (<a href="https://redirect.github.com/remix-run/react-router/pull/15238">#15238</a>)</li>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<h2>v7.17.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<h2>v7.16.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Remove stale/invalid <code>unpkg</code> field from <code>package.json</code>. This was removed from other packages with the release of v7 but missed in the <code>react-router-dom</code> re-export package (<a href="https://redirect.github.com/remix-run/react-router/pull/15075">#15075</a>)</li>
<li>Updated dependencies:
<ul>
<li><a href="https://github.com/remix-run/react-router/releases/tag/[email protected]"><code>[email protected]</code></a></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a> Release v7.18.4 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a> Release v7.18.3 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15424">#15424</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/69a653ee6ab1ac95b13c917ec56c5f3dc17ca9c1"><code>69a653e</code></a> Release v7.18.2 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15354">#15354</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/afdf85d3c15448a41017514caca2aca038d3e9ca"><code>afdf85d</code></a> Release v7.18.1 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15253">#15253</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/2ecaa1ddbbcd583999dda46dd5413e907e8a46f3"><code>2ecaa1d</code></a> Fix react-router-dom main entry metadata (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15238">#15238</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/6fb1e79f8304eddd8b78759edea83cb32389ebf5"><code>6fb1e79</code></a> Release v7.18.0 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15187">#15187</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/195a0d03c1417127ccee73853058c8521beb4fce"><code>195a0d0</code></a> Release v7.17.0 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15145">#15145</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/8984d23f86ca7ae5655711744b77816090bda4e6"><code>8984d23</code></a> Release v7.16.0 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15105">#15105</a>)</li>
<li><a href="https://github.com/remix-run/react-router/commit/3ed77afcde0ad9aea79f1afe5f05a700b201f289"><code>3ed77af</code></a> chore: format</li>
<li><a href="https://github.com/remix-run/react-router/commit/e96962bc6159a2290632849b55872a3878753342"><code>e96962b</code></a> fix: remove stale unpkg field from react-router-dom (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15075">#15075</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router-dom">compare view</a></li>
</ul>
</details>
<br />
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/FelisMC/Felis/network/alerts).
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps react-router to 7.18.4 and updates ancestor dependency react-router-dom. These dependencies need to be updated together.
Updates
react-routerfrom 6.30.4 to 7.18.4Release notes
Sourced from react-router's releases.
... (truncated)
Changelog
Sourced from react-router's changelog.
... (truncated)
Commits
1b1e0b0Release v7.18.4 (#15498)3e4d295[v7] Skip view transitions on revalidation and initial hydration (#15485)e0c6b5bFix HTML attribute escaping for RSC redirects (#15492)23166dfRelease v7.18.3 (#15424)38af67fValidate client-side navigation targets (#15446)df78a29Revert "fix: normalize control characters in relative URLs (#15422)" (#15441)d1a4b1dfix: normalize control characters in relative URLs (#15422)e7c2d94Revert "fix: normalize RSC server redirects (#15421)" (#15434)e4b70d6fix: validate schemeful action origins (#15420)b137cabfix: normalize RSC server redirects (#15421)Updates
react-router-domfrom 6.30.4 to 7.18.4Release notes
Sourced from react-router-dom's releases.
Changelog
Sourced from react-router-dom's changelog.
... (truncated)
Commits
1b1e0b0Release v7.18.4 (#15498)23166dfRelease v7.18.3 (#15424)69a653eRelease v7.18.2 (#15354)afdf85dRelease v7.18.1 (#15253)2ecaa1dFix react-router-dom main entry metadata (#15238)6fb1e79Release v7.18.0 (#15187)195a0d0Release v7.17.0 (#15145)8984d23Release v7.16.0 (#15105)3ed77afchore: formate96962bfix: remove stale unpkg field from react-router-dom (#15075)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.