Skip to content

Conversation

@chrisshino
Copy link
Contributor

Summary

This PR bumps vulnerable Remix/React Router Node packages to safe versions:

  • @remix-run/node >= 2.17.2
  • @react-router/node >= 7.9.4
  • @remix-run/deno >= 2.17.2

Context

This addresses a security advisory for the packages above.

Updated packages

  • @remix-run/node@^2.17.2

Notes

No lockfile detected; updated package.json only.

@kdaviduik kdaviduik requested a review from a team as a code owner January 17, 2026 00:36
@shopify
Copy link
Contributor

shopify bot commented Jan 17, 2026

Oxygen deployed a preview of your security/bump-remix-node-20260114-hydrogen branch. Details:

Storefront Status Preview link Deployment details Last update (UTC)
Skeleton (skeleton.hydrogen.shop) ✅ Successful (Logs) Preview deployment Inspect deployment January 17, 2026 1:07 AM

Learn more about Hydrogen's GitHub integration.

@kdaviduik kdaviduik force-pushed the security/bump-remix-node-20260114-hydrogen branch from e3eeaec to 07debc7 Compare January 17, 2026 00:46
@kdaviduik kdaviduik merged commit f01dda1 into main Jan 17, 2026
12 of 13 checks passed
@kdaviduik kdaviduik deleted the security/bump-remix-node-20260114-hydrogen branch January 17, 2026 01:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants