-
Notifications
You must be signed in to change notification settings - Fork 4.1k
[Snyk] Upgrade react-hook-form from 7.62.0 to 7.69.0 #9588
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Snyk has created this PR to upgrade react-hook-form from 7.62.0 to 7.69.0. See this package in npm: react-hook-form See this project in Snyk: https://app.snyk.io/org/continue-dev-inc.-default/project/c5fb30df-a06c-44cb-83af-5ada5ff6e4a9?utm_source=github&utm_medium=referral&page=upgrade-pr
|
|
✅ Review Complete Code Review Summary |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
1 issue found across 1 file
Prompt for AI agents (all issues)
Check if these issues are valid — if so, understand the root cause of each and fix them.
<file name="gui/package.json">
<violation number="1" location="gui/package.json:59">
P2: react-hook-form bumped in package.json without updating gui/package-lock.json; lock still resolves 7.62.0, so the upgrade won’t apply</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
|
🎉 This PR is included in version 1.8.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Snyk has created this PR to upgrade react-hook-form from 7.62.0 to 7.69.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 8 versions ahead of your current version.
The recommended version was released a month ago.
Issues fixed by the recommended upgrade:
SNYK-JS-DAGRED3ES-13110069
Release notes
Package name: react-hook-form
-
7.69.0 - 2025-12-20
-
7.68.0 - 2025-12-03
import { useForm, FormStateSubscribe } from 'react-hook-form';
-
7.67.0 - 2025-11-28
useForm({
-
7.66.1 - 2025-11-17
-
7.66.0 - 2025-10-31
-
7.65.0 - 2025-10-10
import { useForm, Watch } from 'react-hook-form';
-
7.64.0 - 2025-10-04
-
7.63.0 - 2025-09-19
-
7.62.0 - 2025-08-01
from react-hook-form GitHub release notes📏 feat: align API with useWatch (#13192)
🤦🏻♂️ chore: update @ deprecated names prop on (#13198)
🏥 chore: safely call function methods on elements (#13190)
🪖 chore: cve-2025-67779 (#13196)
🪖 chore: cve-2025-55184 & cve-2025-55183 (#13194)
🪖 chore: CVE-2025-55182 Critical RCE vulnerabilty (#13175)
🔬 test: add regression tests for #12837 and #13136 (#13187)
🐞 fix(reset): preserve isValid state when keepIsValid option is used (#13173)
🐞 fix: ensure each createFormControl.subscribe subscription listens only to the changes it subscribes to (#12968)
🐞 fix(validation): batch isValidating state updates with validation result (#13181)
🐞 fix(createFormControl): resolve race condition between setError and setFocus (#13138) (#13169)
🧿 fix control prop type (#13189)
🔔 chore: clean cloneObject logic (#13179)
thanks to @ PierreCrb, @ a28689604, @ AnuragM7666, @ ap0nia, @ dusan233 & @ hlongc
🎧 feat:
<FormStateSubscribe />component (#13142)const App = () => {
const { register, control } = useForm();
return (
<div>
<form>
<input {...register('foo')} />
<input {...register('bar')} />
</form>
{/* re-render only when formState of
foochanges */}<FormStateSubscribe
control={control}
name={"foo"}
render={({errors}) => <span>{errors.foo?.message}</span>}
/>
</div>
);
};
🐞 fix: clear validation errors synchronously in reset() to fix Next.js 16 Server Actions issue (#13139)
Revert "✨ fix(types): allow undefined value with async defaultValues in Contr…" (#13171)
thanks to @ xiangnuans, @ abnud11, @ ntatoud & @ ap0nia
🎯 feat: add exact to useController props (#13154)
defaultValues: {
user: {
name: ''
}
}
})
<Controller control={control} name="user" exact={false} /> // subscribe to all user object
✨ fix(types): allow undefined value with async defaultValues in Controller (#13160)
🐞 fix(types): correct PathValueImpl type inference (#13150)
thanks to @ ap0nia, @ Fasping & @ joseph0926
⚡ perf: reduce redundant property access in getDirtyFields (#13146)
🐞 fix(createFormControl): skip setValid() during batch array updates (#13140)
🐞 fix(useForm): recompute isValid after reset when values update asynchronously (#13126)
🐞 fix(deepEqual): handle NaN comparison correctly using Object.is (#13120)
thanks to @ kimtaejin3, @ a28689604 & @ WuMingDao
🎥 feat: make
useWatchanduseControllerto react to name change (#13070)🐛 fix:
watch()returningundefinedimmediately afterreset()- Issue #13088 (#13091)🐞 fix
<Watch />: correct render function parameter typing (#13108)thanks to @ aspirisen, @ scato3, @ dusan233 & @ zoldyzdk
🧿 feat:
<Watch />component (#12986)const App = () => {
const { register, control } = useForm();
return (
<div>
<form>
<input {...register('foo')} />
<input {...register('bar')} />
</form>
{/* re-render only when value of
foochanges */}<Watch
control={control}
names={['foo']}
render={([foo]) => <span>{foo}</span>}
/>
</div>
);
};
🐞 fix: respect parent-provided
useFieldArrayrules (#13082) (#13083🐞 fix:
getDirtyFieldssubmit fields with null values when usinguseForm(#13079)thanks to @ tesseractjh, @ Han5991 & @ jonathanarnault
🚏 Support optional array fields in
PathValueImpltype (#13057)🐞 fix: preserve Controller's defaultValue with
shouldUnregisterprop (#13063)✂ chore: remove unused field ids ref in
useFieldArray(#13066)thanks to @ MPrieur-chaps, @ gynekolog & @ uk960214
🥢 feat: extract form values by form state (#12936)
🦍 feat: improve get dirty fields logic (#13049)
🐿️ chore: remove duplicated function isMessage (#13050)
🐞 fix: use field name to update isValidating fields (#13000)
🐞 fix: unregister previous field when switching conditional Controllers (#13041)
🐞 fix: only excuse trigger function when deps has a valid array (#13056)
thanks to @ candymask0712, @ GorkemKir, @ kimtaejin3, @ m2na7 & @ abnud11
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
Continue Tasks
Powered by Continue
Summary by cubic
Upgrade react-hook-form to ^7.69.0 (locks to 7.71.1) to pull in bug fixes, minor performance improvements, and upstream security patches. This is a non-breaking v7 update; no app code changes expected.
Written for commit 617fd11. Summary will update on new commits.