Skip to content

fix: update React to 19.1.2 to address CVE-2025-55182#5387

Merged
tomiir merged 1 commit intomainfrom
devin/1764796511-update-react-cve-2025-55182
Dec 3, 2025
Merged

fix: update React to 19.1.2 to address CVE-2025-55182#5387
tomiir merged 1 commit intomainfrom
devin/1764796511-update-react-cve-2025-55182

Conversation

@devin-ai-integration
Copy link
Copy Markdown
Contributor

@devin-ai-integration devin-ai-integration bot commented Dec 3, 2025

Description

Updates React and React DOM from 19.1.1 to 19.1.2 in the demo and laboratory apps to address the critical security vulnerability CVE-2025-55182 affecting React Server Components.

Reference: https://x.com/reactjs/status/1996244264192274535

Type of change

  • Chore (non-breaking change that addresses non-functional tasks, maintenance, or code quality improvements)
  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

Associated Issues

N/A - Security patch for CVE-2025-55182

Checklist

  • Code in this PR is covered by automated tests (Unit tests, E2E tests)
  • My changes generate no new warnings
  • I have reviewed my own code
  • I have filled out all required sections
  • I have tested my changes on the preview link
  • Approver of this PR confirms that the changes are tested on the preview link

Human Review Checklist

  • Verify React 19.1.2 is the correct patched version for CVE-2025-55182
  • Confirm CI/E2E tests pass for both laboratory and demo apps
  • Verify no regressions in app functionality

Link to Devin run: https://app.devin.ai/sessions/bf93d58388204da89f14c6ff80e27515
Requested by: tomas@reown.com (@tomiir)

Co-Authored-By: tomas@reown.com <rocchitomas@gmail.com>
@changeset-bot
Copy link
Copy Markdown

changeset-bot bot commented Dec 3, 2025

⚠️ No Changeset found

Latest commit: 2b9ddc8

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@devin-ai-integration
Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@vercel
Copy link
Copy Markdown

vercel bot commented Dec 3, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
appkit-basic-html Ready Ready Preview Comment Dec 3, 2025 9:23pm
appkit-demo Ready Ready Preview Comment Dec 3, 2025 9:23pm
appkit-gallery Ready Ready Preview Comment Dec 3, 2025 9:23pm
appkit-headless-sample-app Ready Ready Preview Comment Dec 3, 2025 9:23pm
appkit-laboratory Ready Ready Preview Comment Dec 3, 2025 9:23pm
10 Skipped Deployments
Project Deployment Preview Comments Updated (UTC)
appkit-basic-example Ignored Ignored Dec 3, 2025 9:23pm
appkit-basic-sign-client-example Ignored Ignored Dec 3, 2025 9:23pm
appkit-basic-up-example Ignored Ignored Dec 3, 2025 9:23pm
appkit-ethers5-bera Ignored Ignored Dec 3, 2025 9:23pm
appkit-nansen-demo Ignored Ignored Dec 3, 2025 9:23pm
appkit-vue-solana Ignored Ignored Dec 3, 2025 9:23pm
appkit-wagmi-cdn-example Ignored Ignored Dec 3, 2025 9:23pm
ethereum-provider-wagmi-example Ignored Ignored Dec 3, 2025 9:23pm
next-wagmi-solana-bitcoin-example Ignored Ignored Dec 3, 2025 9:23pm
vue-wagmi-example Ignored Ignored Dec 3, 2025 9:23pm

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 3, 2025

Visual Regression Test Results ✅ Passed

✨ No visual changes detected

Chromatic Build: https://www.chromatic.com/build?appId=6493191bf4b10fed8ca7353f&number=479
Storybook Preview: https://6493191bf4b10fed8ca7353f-pfxykbqspf.chromatic.com/

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedclass-variance-authority@​0.7.11001006880100
Added@​walletconnect/​sign-client@​2.23.0100100779780
Addedclsx@​2.1.11001009680100
Addedpostcss@​8.5.31001008284100
Addedchalk@​4.1.210010010083100
Addedtailwindcss@​4.1.171001008498100
Addedtw-animate-css@​1.4.01001009488100
Addedsemver@​7.7.210010010089100
Added@​tailwindcss/​postcss@​4.1.1710010010099100

View full report

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 3, 2025

📦 Bundle Size Check

All bundles are within size limits

📊 View detailed bundle sizes

> @reown/appkit-monorepo@1.7.1 size /home/runner/work/appkit/appkit


> size-limit

@reown/appkit - Main Entry
Size limit:   80 kB
Size:         71.36 kB with all dependencies, minified and gzipped
Loading time: 1.4 s    on slow 3G
Running time: 456 ms   on Snapdragon 410
Total time:   1.9 s
@reown/appkit/react
Size limit:   230 kB
Size:         228.31 kB with all dependencies, minified and gzipped
Loading time: 4.5 s     on slow 3G
Running time: 986 ms    on Snapdragon 410
Total time:   5.5 s
@reown/appkit/vue
Size limit:   80 kB
Size:         71.36 kB with all dependencies, minified and gzipped
Loading time: 1.4 s    on slow 3G
Running time: 382 ms   on Snapdragon 410
Total time:   1.8 s
@reown/appkit-scaffold-ui
Size limit:   220 kB
Size:         209.4 kB with all dependencies, minified and gzipped
Loading time: 4.1 s    on slow 3G
Running time: 773 ms   on Snapdragon 410
Total time:   4.9 s
@reown/appkit-ui
Size limit:   500 kB
Size:         13.15 kB with all dependencies, minified and gzipped
Loading time: 257 ms   on slow 3G
Running time: 72 ms    on Snapdragon 410
Total time:   329 ms

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 3, 2025

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 79.71% 38341 / 48097
🔵 Statements 79.71% 38341 / 48097
🔵 Functions 77.3% 4107 / 5313
🔵 Branches 86.62% 9300 / 10736
File CoverageNo changed files found.
Generated in workflow #16451 for commit 2b9ddc8 by the Vitest Coverage Report Action

@tomiir tomiir added this pull request to the merge queue Dec 3, 2025
@tomiir tomiir removed this pull request from the merge queue due to a manual request Dec 3, 2025
@tomiir tomiir merged commit 775595d into main Dec 3, 2025
63 of 64 checks passed
@tomiir tomiir deleted the devin/1764796511-update-react-cve-2025-55182 branch December 3, 2025 22:26
@github-actions github-actions bot locked and limited conversation to collaborators Dec 3, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant