Skip to content

Conversation

@lukebowerman
Copy link

Update valibot to address a high severity vulnerability described in GHSA-vqpr-j7v3-hqw9.

This is a similar change to remix-run/react-router#14608 but targeting the Remix v2 series.

@lukebowerman
Copy link
Author

@brophdawg11 This is the aforementioned PR to patch-up valibot version for the 2.x series of Remix.

Reference: remix-run/react-router#14623 (comment)

@MichaelDeBoey MichaelDeBoey changed the title chore(dev): update valibot deps(dev): update valibot Dec 16, 2025
@MichaelDeBoey MichaelDeBoey added dependencies Pull requests that update a dependency file v2 Issues related to v2 apis labels Dec 16, 2025
@lukebowerman
Copy link
Author

MSEdge CI failure appears like to be a flake perhaps?

@brophdawg11
Copy link
Contributor

Thanks! Yeah the edge tests can be flaky, especially the HMR tests

@brophdawg11 brophdawg11 merged commit b6aec07 into remix-run:v2 Dec 17, 2025
8 of 9 checks passed
@lukebowerman
Copy link
Author

Thank you for getting this merged. I see that 2.17.3 has been cut but not yet published to NPM. Any ETA on when that will happen? Thank you! :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed dependencies Pull requests that update a dependency file v2 Issues related to v2 apis

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants