Repository navigation
[SDK-757] Clear react-router Dependabot alerts in the examples - #173
devtools-agent[bot] wants to merge 2 commits into
Conversation
The four open alerts (GHSA-wrjc-x8rr-h8h6, GHSA-337j-9hxr-rhxg) are for react-router 6.30.6, pulled in by react-router-dom in two examples. Only react-router >= 7.18.0 is patched, and React Router 7 requires React 18+. - examples/react-17: drop react-router-dom. No patched React Router supports React 17, and this example exists to show the SDK on React 17. App.jsx now switches between its two pages with a small pushState-based NavLink, keeping the same URLs, active-link styling and per-page RollbarContext wrappers. Adds a navigation test and Testing Library cleanup between tests. - examples/typescript: upgrade to React 19 and react-router 7.18.4 (imported from `react-router`, which replaces react-router-dom in v7). Moves index.tsx to createRoot, bumps @types/react(-dom) to 19 and @testing-library/react to 16 (with its @testing-library/dom peer), and removes ExampleErrors.propTypes, which React 19 ignores. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI Agent Review (openai, openai-astra)SummaryThis PR clears the react-router Dependabot alerts in two examples:
What I checked
Non-blocking notes
No blocking issues found. I could not run the tests or the build, so this review does not say whether they pass. |
brianr
left a comment
There was a problem hiding this comment.
Fix these issues:
examples/index.js:10 still imports react-router-dom. It is a standalone snippet outside any example package and is not in this diff, but it now describes an API the examples no longer use.
The react-17 page switch compares paths exactly, so /error-boundary/ (trailing slash) now shows Playground. That doesn't matter for a demo app.
- examples/index.js and the README's "Using with React Router" section still used the React Router 5 API (react-router-dom, Switch, Route children). Move both to the React Router 7 API the TypeScript example uses (react-router, Routes, Route element), rename the snippet's Routes component to AppRoutes so it no longer shadows the import, and define the README's missing [React Router] link. - examples/react-17: ignore trailing slashes in the current path, as React Router did, so /error-boundary/ shows the ErrorBoundary page instead of falling back to the playground. Adds a test for it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI Agent Review (openai, openai-astra)Review: SDK-757, removing react-router from the examplesI read the full diff and the files it touches in the checkout, plus what they depend on: the library source in React 17 example (
|
Resolves Linear SDK-757: clears all 4 open Dependabot alerts on this repo (Option A from the ticket thread, with the TS example on React 19).
Alerts
All four are for
react-router6.30.6, pulled in byreact-router-domin two examples. None affect the published@rollbar/reactpackage.examples/react-17examples/react-17examples/typescriptexamples/typescriptThe first patched release is
react-router7.18.0, and React Router 7 needs React 18+. This is why Dependabot's #167 failsnpm ciwithERESOLVE. React Router 8 isn't an option because it needs Node >= 22.22 and CI still covers Node 20.Changes
examples/react-17: remove React Routersrc/App.jsxnow has a smallusePathnamehook andNavLinkbuilt onpushState/popstate. URLs (/,/error-boundary),.active/aria-currentstyling, the fallback to the playground for unknown paths, and the per-pageRollbarContextwrappers all stay as they were.src/index.jsxno longer wraps the app inBrowserRouter.MemoryRouter. There's a new test for header navigation, andsetupTests.jsnow calls Testing Library'scleanupafter each test, because Vitest'safterEachisn't global.examples/typescript: React 19 + React Router 7react/react-dom^19.3.0,@types/react/@types/react-dom^19.3.0.react-router-dom^6 is replaced byreact-router^7.18.4. In v7,react-router-domonly re-exportsreact-router.src/index.tsx:ReactDOM.renderis replaced bycreateRoot.@testing-library/reactgoes from 12 to 16, plus its required@testing-library/dom^10 peer.ExampleErrors.propTypes, because React 19 ignorespropTypes. Theprop-typesdependency stays because@rollbar/reactlists it as a peer.@testing-library/dom8 tree.Validation
Ran locally on Node 20, following the CI steps:
npm run install:all -- ci: passes, with noERESOLVE.npm run lint,lint:examples,typecheck,build:all(includingtsc && vite buildfor the TS example),test,test:examples: all pass. react-17 has 3 tests and typescript has 1.npm auditin both examples: no vulnerabilities.react-17no longer has anyreact-routerin its lockfile, andtypescriptresolvesreact-router@7.18.4.Review follow-up (8b71633)
examples/index.jsand the README's "Using with React Router" section used the React Router 5 API (react-router-dom,Switch,<Route>with children). Both now use the React Router 7 API that the TS example uses (react-router,Routes,<Route element>).Routescomponent is renamed toAppRoutes, so it no longer shadows theRoutesimport.[React Router]without ever defining that link, so I added the definition.examples/react-17: trailing slashes.usePathnamenow strips trailing slashes, as React Router did, so/error-boundary/shows the ErrorBoundary page and marks its nav link active. There's a new test for this; react-17 now has 4 tests.install:all -- ci,lint,lint:examples,typecheck,build:all,testandtest:examplesall pass. Prettier is clean on the changed files.Follow-ups
🤖 Generated with Claude Code