build(deps): Bump react-dom from 19.2.7 to 19.2.8 - #1071
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
🤖 Cursor Dependency AnalysisSupply-Chain Malware ReviewI'll review the upstream diff and scanner findings for supply-chain compromise indicators.Verdict: benign Patch bump Evidence
Compatibility AnalysisI'll analyze how Patch bump with no 1) Usage in this repo
2) Intersection with upstream changesBetween Behavioral commit 3) Risks / unknowns
4) Recommendationmerge — safe patch; no adoption blockers. Optional follow-up: bump Malware Scan Summary
Top findings
|
Bumps [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) from 19.2.7 to 19.2.8. - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom) --- updated-dependencies: - dependency-name: react-dom dependency-version: 19.2.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
9779e18 to
e44704e
Compare
Bumps react-dom from 19.2.7 to 19.2.8.
Release notes
Sourced from react-dom's releases.
Commits
1dd4ecb[FlightReply] Performance improvements when decoding (#37087)b0d2fdb[19.2.x] Update required references to GitHub repo (#36753)Note
Low Risk
Patch-level React update for a Docusaurus docs site with no source changes; typical low-impact dependency maintenance.
Overview
Bumps
react-domfrom 19.2.7 to 19.2.8 inpackage.jsonand refreshespackage-lock.json, which also resolvesreactto 19.2.8 to matchreact-dom’s peer dependency.This is a patch release; upstream notes focus on React Server Components decode performance, with no app code changes in this repo.
Reviewed by Cursor Bugbot for commit e44704e. Bugbot is set up for automated code reviews on this repo. Configure here.