Skip to content

Conversation

@jdomeracki-coder
Copy link
Contributor

Reference:
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Please note that coder deployments aren't vulnerable since React Server Components aren't in use

@jdomeracki-coder jdomeracki-coder added the cherry-pick/v2.29 Needs to be cherry-picked to the 2.29 release branch label Dec 8, 2025
Co-authored-by: blink-so[bot] <211532188+blink-so[bot]@users.noreply.github.com>
@github-actions
Copy link

github-actions bot commented Dec 8, 2025


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


1 out of 2 committers have signed the CLA.
✅ (jdomeracki-coder)[https://github.com/jdomeracki-coder]
❌ @blinkagent[bot]
You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@david-fraley david-fraley merged commit 59cdd7e into release/2.29 Dec 9, 2025
29 of 31 checks passed
@david-fraley david-fraley deleted the react-upgrade-CVE-2025-55182 branch December 9, 2025 15:34
@github-actions github-actions bot locked and limited conversation to collaborators Dec 9, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

cherry-pick/v2.29 Needs to be cherry-picked to the 2.29 release branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants