[Snyk] Upgrade react-hook-form from 7.62.0 to 7.69.0#9588
Conversation
Snyk has created this PR to upgrade react-hook-form from 7.62.0 to 7.69.0. See this package in npm: react-hook-form See this project in Snyk: https://app.snyk.io/org/continue-dev-inc.-default/project/c5fb30df-a06c-44cb-83af-5ada5ff6e4a9?utm_source=github&utm_medium=referral&page=upgrade-pr
|
|
✅ Review Complete Code Review Summary |
There was a problem hiding this comment.
1 issue found across 1 file
Prompt for AI agents (all issues)
Check if these issues are valid — if so, understand the root cause of each and fix them.
<file name="gui/package.json">
<violation number="1" location="gui/package.json:59">
P2: react-hook-form bumped in package.json without updating gui/package-lock.json; lock still resolves 7.62.0, so the upgrade won’t apply</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
|
🎉 This PR is included in version 1.8.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.40.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Snyk has created this PR to upgrade react-hook-form from 7.62.0 to 7.69.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 8 versions ahead of your current version.
The recommended version was released a month ago.
Issues fixed by the recommended upgrade:
SNYK-JS-DAGRED3ES-13110069
Release notes
Package name: react-hook-form
-
7.69.0 - 2025-12-20
-
7.68.0 - 2025-12-03
import { useForm, FormStateSubscribe } from 'react-hook-form';
-
7.67.0 - 2025-11-28
useForm({
-
7.66.1 - 2025-11-17
-
7.66.0 - 2025-10-31
-
7.65.0 - 2025-10-10
import { useForm, Watch } from 'react-hook-form';
-
7.64.0 - 2025-10-04
-
7.63.0 - 2025-09-19
-
7.62.0 - 2025-08-01
from react-hook-form GitHub release notes📏 feat: align API with useWatch (#13192)
🤦🏻♂️ chore: update @ deprecated names prop on (#13198)
🏥 chore: safely call function methods on elements (#13190)
🪖 chore: cve-2025-67779 (#13196)
🪖 chore: cve-2025-55184 & cve-2025-55183 (#13194)
🪖 chore: CVE-2025-55182 Critical RCE vulnerabilty (#13175)
🔬 test: add regression tests for #12837 and #13136 (#13187)
🐞 fix(reset): preserve isValid state when keepIsValid option is used (#13173)
🐞 fix: ensure each createFormControl.subscribe subscription listens only to the changes it subscribes to (#12968)
🐞 fix(validation): batch isValidating state updates with validation result (#13181)
🐞 fix(createFormControl): resolve race condition between setError and setFocus (#13138) (#13169)
🧿 fix control prop type (#13189)
🔔 chore: clean cloneObject logic (#13179)
thanks to @ PierreCrb, @ a28689604, @ AnuragM7666, @ ap0nia, @ dusan233 & @ hlongc
🎧 feat:
<FormStateSubscribe />component (#13142)const App = () => {
const { register, control } = useForm();
return (
<div>
<form>
<input {...register('foo')} />
<input {...register('bar')} />
</form>
{/* re-render only when formState of
foochanges */}<FormStateSubscribe
control={control}
name={"foo"}
render={({errors}) => <span>{errors.foo?.message}</span>}
/>
</div>
);
};
🐞 fix: clear validation errors synchronously in reset() to fix Next.js 16 Server Actions issue (#13139)
Revert "✨ fix(types): allow undefined value with async defaultValues in Contr…" (#13171)
thanks to @ xiangnuans, @ abnud11, @ ntatoud & @ ap0nia
🎯 feat: add exact to useController props (#13154)
defaultValues: {
user: {
name: ''
}
}
})
<Controller control={control} name="user" exact={false} /> // subscribe to all user object
✨ fix(types): allow undefined value with async defaultValues in Controller (#13160)
🐞 fix(types): correct PathValueImpl type inference (#13150)
thanks to @ ap0nia, @ Fasping & @ joseph0926
⚡ perf: reduce redundant property access in getDirtyFields (#13146)
🐞 fix(createFormControl): skip setValid() during batch array updates (#13140)
🐞 fix(useForm): recompute isValid after reset when values update asynchronously (#13126)
🐞 fix(deepEqual): handle NaN comparison correctly using Object.is (#13120)
thanks to @ kimtaejin3, @ a28689604 & @ WuMingDao
🎥 feat: make
useWatchanduseControllerto react to name change (#13070)🐛 fix:
watch()returningundefinedimmediately afterreset()- Issue #13088 (#13091)🐞 fix
<Watch />: correct render function parameter typing (#13108)thanks to @ aspirisen, @ scato3, @ dusan233 & @ zoldyzdk
🧿 feat:
<Watch />component (#12986)const App = () => {
const { register, control } = useForm();
return (
<div>
<form>
<input {...register('foo')} />
<input {...register('bar')} />
</form>
{/* re-render only when value of
foochanges */}<Watch
control={control}
names={['foo']}
render={([foo]) => <span>{foo}</span>}
/>
</div>
);
};
🐞 fix: respect parent-provided
useFieldArrayrules (#13082) (#13083🐞 fix:
getDirtyFieldssubmit fields with null values when usinguseForm(#13079)thanks to @ tesseractjh, @ Han5991 & @ jonathanarnault
🚏 Support optional array fields in
PathValueImpltype (#13057)🐞 fix: preserve Controller's defaultValue with
shouldUnregisterprop (#13063)✂ chore: remove unused field ids ref in
useFieldArray(#13066)thanks to @ MPrieur-chaps, @ gynekolog & @ uk960214
🥢 feat: extract form values by form state (#12936)
🦍 feat: improve get dirty fields logic (#13049)
🐿️ chore: remove duplicated function isMessage (#13050)
🐞 fix: use field name to update isValidating fields (#13000)
🐞 fix: unregister previous field when switching conditional Controllers (#13041)
🐞 fix: only excuse trigger function when deps has a valid array (#13056)
thanks to @ candymask0712, @ GorkemKir, @ kimtaejin3, @ m2na7 & @ abnud11
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
Continue Tasks
Powered by Continue
Summary by cubic
Upgrade react-hook-form to ^7.69.0 (locks to 7.71.1) to pull in bug fixes, minor performance improvements, and upstream security patches. This is a non-breaking v7 update; no app code changes expected.
Written for commit 617fd11. Summary will update on new commits.