Skip to content

Tech debt: react-router-dom stuck on v6.30.6 (unpatched advisories) due to dead src/ tree #134

Description

@jonathanp-okta

Description

react-router-dom is pinned at 6.30.6 and has two remaining moderate-severity advisories that are only patched in 7.18.3+:

These are already public advisories (not a new disclosure), flagged here for tracking, not reported as a fresh vulnerability.

The blocker: this is a semver-major bump (v6 → v7), and the app still uses the legacy v6 API (BrowserRouter / Routes / Route in src/app.js). A version-only bump risks breaking routing, so it needs a real migration pass rather than a dependabot-style patch.

While investigating, it looks like src/ (app.js, components/, etc.) may itself be dead code — a leftover from the pre-ui-redesign webpack-based React app:

  • Nothing in the current Next.js app/ router imports from src/.
  • No test references it.
  • It isn't part of the next build output.

src/ is the only reason react-router-dom is a direct dependency at all — the live app doesn't route through it. If src/ is confirmed unused and removed, react-router-dom (and this advisory) can likely be dropped from package.json entirely, which would resolve this without a v7 migration.

Expected outcome: either (a) confirm src/ is dead, delete it, and drop react-router-dom, or (b) if src/ is still needed for some reason, migrate it to react-router-dom v7 to clear the advisories.

Reproduction

  1. Run npm ls react-router-dom --all on ui-redesign — shows react-router-dom@6.30.6 as a direct dependency.
  2. Run npm audit — reports the two advisories above against react-router-dom/react-router, both listing a fix only via 7.18.3 (isSemVerMajor: true).
  3. Search the codebase for consumers: grep -rn "from 'react-router-dom'" — only hits are in src/app.js, src/components/app.js, src/components/hero.js. None of these are imported from the Next.js app/ directory, any test file, or referenced in next build output.

Not consistently reproducible as a runtime bug — this is a static dependency/dead-code finding from an npm audit + npm ls + import-graph review, not an observed failure.

Environment

  • Version of this library used: react-router-dom@6.30.6
  • Version of the platform or framework used, if applicable: Next.js 16.3.5 (App Router), Node.js >=22.0.0
  • Other relevant versions (language, server software, OS, browser): TypeScript 5.9.3, npm (lockfileVersion per package-lock.json)
  • Other modules/plugins/libraries that might be involved: react@19.2.0, react-dom@19.2.0 — note src/app.js still calls the legacy ReactDOM.render API alongside react-router-dom v6, another sign this tree predates the React 19 / App Router migration

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions