Skip to content

chore(deps): bump react from 19.2.4 to 19.2.6 in /web - #13

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/react-19.2.6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/react-19.2.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor

Bumps react from 19.2.4 to 19.2.6.

Release notes

Sourced from react's releases.

19.2.6 (May 6th, 2026)

React Server Components

19.2.5 (April 8th, 2026)

React Server Components

Commits

@dependabot @github

dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from acamarata as a code owner May 17, 2026 19:22
@vercel

vercel Bot commented May 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
islamwiki Ready Ready Preview, Comment May 18, 2026 11:13am
ummat-islamwiki Ready Ready Preview, Comment May 18, 2026 11:13am

Request Review

@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 10 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
next HIGH 1117930 Upgrade to version 16.2.5 or later
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later
next HIGH 1118949 Upgrade to version 16.2.5 or later
next HIGH 1118953 Upgrade to version 16.2.5 or later
next HIGH 1118955 Upgrade to version 16.2.5 or later
next HIGH 1118959 Upgrade to version 16.2.5 or later
next HIGH 1118961 Upgrade to version 16.2.5 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 4 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

Bumps [react](https://github.com/facebook/react/tree/HEAD/packages/react) from 19.2.4 to 19.2.6.
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react)

---
updated-dependencies:
- dependency-name: react
  dependency-version: 19.2.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/react-19.2.6 branch from 1f277bf to d25b9ff Compare May 18, 2026 11:11
@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 4 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@dependabot @github

dependabot Bot commented on behalf of github Jun 3, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #20.

@dependabot dependabot Bot closed this Jun 3, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/web/react-19.2.6 branch June 3, 2026 04:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants