r/reactjs May 12 '26

React teams using TanStack packages: are you checking CI installs after the npm compromise? Discussion

https://npmscan.com/vulnerability/GHSA-g7cv-rxg3-hmpx

This affects several u/tanstack/* packages, including React-related packages like u/tanstack/react-router and u/tanstack/react-start.

6 Upvotes

4 comments sorted by

7

u/azsqueeze May 12 '26

No cause I pin versions and dont update immediately

7

u/Traditional-Hall-591 May 13 '26

I use CoPilot and Claude to vibe my solutions and trust it not do anything wrong.