Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Patch FlightReplyServer with fixes from ReactFlightClient - #35277

Merged
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver
Dec 3, 2025
Merged

Patch FlightReplyServer with fixes from ReactFlightClient#35277
sebmarkbage merged 1 commit into
react:mainfrom
sebmarkbage:patchreplyserver

Conversation

@sebmarkbage

Copy link
Copy Markdown
Contributor

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.

We did a number of refactors to ReactFlightClient in PRs like #29823 and #33664 to change the structure of the resolution. This PR brings those changes to synchronize the two approaches. Which addresses deep resolution of cycles and deferred error handling.

This also fixes a critical security vulnerability.

FlightReplyServer are for client->server and ReactFlightClient is for server->client. They're not 100% symmetrical.
We did a number of refactors to ReactFlightClient in PRs like react#29823 and react#33664 to change the structure of the resolution.
This PR brings those changes to synchronize the two approaches. Which addresses
deep resolution of cycles and deferred error handling.
This also fixes a critical security vulnerability.
@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Dec 3, 2025
@sebmarkbage
sebmarkbage merged commit 7dc903c into react:mainDec 3, 2025
238 of 243 checks passed
@react-sizebot

Copy link
Copy Markdown

Comparing: 36df5e8...e2fd5dc

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=608.36 kB608.36 kB=107.68 kB107.68 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=667.47 kB667.47 kB=117.57 kB117.57 kB
facebook-www/ReactDOM-prod.classic.js=693.67 kB693.67 kB=122.06 kB122.06 kB
facebook-www/ReactDOM-prod.modern.js=684.10 kB684.10 kB=120.45 kB120.45 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB

Significant size changes

Includes any change greater than 0.2%:

Expand to show
Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.76%94.85 kB103.16 kB+7.05%19.44 kB20.81 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.72%98.46 kB107.04 kB+6.91%20.20 kB21.59 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.68%95.99 kB104.32 kB+6.96%19.70 kB21.07 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.production.js+8.60%96.70 kB105.01 kB+6.90%19.81 kB21.18 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.production.js+8.56%100.31 kB108.90 kB+6.80%20.57 kB21.97 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.production.js+8.52%97.84 kB106.17 kB+6.80%20.10 kB21.46 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.48%102.29 kB110.97 kB+6.92%20.73 kB22.16 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.production.js+8.33%104.15 kB112.82 kB+6.78%21.09 kB22.52 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+8.11%101.91 kB110.18 kB+6.52%20.57 kB21.91 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+8.08%102.26 kB110.53 kB+6.43%20.67 kB22.00 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+8.04%103.07 kB111.35 kB+6.42%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+8.04%103.07 kB111.36 kB+6.41%20.87 kB22.21 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.98%108.37 kB117.01 kB+6.47%21.67 kB23.07 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.production.js+7.97%103.76 kB112.03 kB+6.13%21.01 kB22.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.production.js+7.94%104.12 kB112.38 kB+6.11%21.11 kB22.40 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.01%21.31 kB22.59 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.production.js+7.90%104.92 kB113.21 kB+6.00%21.31 kB22.59 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.89%109.42 kB118.05 kB+6.29%21.92 kB23.30 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.89%109.44 kB118.07 kB+6.27%21.92 kB23.30 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.production.js+7.84%110.22 kB118.87 kB+6.35%22.05 kB23.45 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.production.js+7.76%111.27 kB119.91 kB+5.97%22.34 kB23.68 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.production.js+7.76%111.29 kB119.92 kB+5.95%22.35 kB23.68 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.93%187.27 kB196.50 kB+4.18%34.00 kB35.42 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.browser.development.js+4.87%189.37 kB198.60 kB+4.05%34.46 kB35.85 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.85%190.94 kB200.19 kB+4.10%34.50 kB35.92 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.edge.development.js+4.79%193.03 kB202.28 kB+3.97%34.96 kB36.35 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.70%195.12 kB204.28 kB+3.84%35.38 kB36.74 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.69%195.59 kB204.76 kB+3.86%35.48 kB36.85 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.browser.development.js+4.65%197.22 kB206.39 kB+3.78%35.81 kB37.17 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.browser.development.js+4.64%197.69 kB206.86 kB+3.82%35.91 kB37.28 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.81%35.87 kB37.23 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.62%198.82 kB208.01 kB+3.79%35.87 kB37.23 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.77%36.30 kB37.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.edge.development.js+4.57%200.91 kB210.10 kB+3.76%36.30 kB37.67 kB
oss-stable-semver/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-stable/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.45%213.53 kB223.03 kB+3.57%38.89 kB40.28 kB
oss-experimental/react-server-dom-esm/cjs/react-server-dom-esm-server.node.development.js+4.41%215.62 kB225.12 kB+3.51%39.35 kB40.73 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.37%219.95 kB229.55 kB+3.30%39.56 kB40.87 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-server.node.development.js+4.33%222.04 kB231.64 kB+3.27%40.02 kB41.33 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.22%226.66 kB236.22 kB+3.15%40.64 kB41.92 kB
oss-stable-semver/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.19%227.87 kB237.41 kB+3.12%40.94 kB42.22 kB
oss-stable-semver/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-stable/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.19%227.92 kB237.46 kB+3.10%40.94 kB42.20 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.unbundled.development.js+4.18%228.75 kB238.31 kB+3.11%41.10 kB42.38 kB
oss-experimental/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js+4.15%229.96 kB239.50 kB+3.09%41.40 kB42.67 kB
oss-experimental/react-server-dom-turbopack/cjs/react-server-dom-turbopack-server.node.development.js+4.15%230.01 kB239.55 kB+3.07%41.39 kB42.66 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.browser.production.js+0.29%58.58 kB58.75 kB+0.47%11.50 kB11.55 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.edge.production.js+0.26%64.11 kB64.28 kB+0.42%12.71 kB12.76 kB
oss-experimental/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable-semver/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB
oss-stable/react-server-dom-parcel/cjs/react-server-dom-parcel-client.node.production.js+0.25%68.44 kB68.61 kB+0.37%13.34 kB13.39 kB

Generated by 🚫 dangerJS against e2fd5dc

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

TL;DR: If you are using React Server Components you really must upgrade.

More information in Critical Security Vulnerability in React Server Components.

This vulnerability was disclosed as CVE-2025-55182 and is rated CVSS 10.0.

@jschauma

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

@sebmarkbage

Copy link
Copy Markdown
ContributorAuthor

Further details of the vulnerability will be provided after the rollout of the fix is complete.

Doridian pushed a commit to foxCaves/foxCaves that referenced this pull request Dec 3, 2025
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.0/19.2.1?slim=true) |
| [react-dom](https://react.dev/) ([source](https://github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.0` -> `19.2.1`](https://renovatebot.com/diffs/npm/react-dom/19.2.0/19.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.0/19.2.1?slim=true) |
---
### Release Notes
<details>
<summary>facebook/react (react)</summary>
### [`v19.2.1`](https://github.com/facebook/react/blob/HEAD/CHANGELOG.md#1921-Dec-3-2025)
[Compare Source](react/react@v19.2.0...v19.2.1)
##### React Server Components
- Bring React Server Component fixes to Server Actions ([@&#8203;sebmarkbage](https://github.com/sebmarkbage) [#&#8203;35277](react/react#35277))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yNy4xIiwidXBkYXRlZEluVmVyIjoiNDIuMjcuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Reviewed-on: https://git.foxden.network/foxCaves/foxCaves/pulls/16
Co-authored-by: Renovate <renovate@foxden.network>
Co-committed-by: Renovate <renovate@foxden.network>
@justinrest

Copy link
Copy Markdown

the meta

@szybnev

This comment was marked as outdated.

@rickhanlonii

Copy link
Copy Markdown
Contributor

@szybnev that PoC is not valid, the server in that PoC is faked to respond.

@matija2209

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

Probably with a reason. You do not want to make it easier to reverse engineer. What we see, they see.

@macropin

macropin commented Dec 4, 2025

Copy link
Copy Markdown

Will the fix be backported to older major versions, or are they not vulnerable?

@eps1lon

Copy link
Copy Markdown
Collaborator

There are no react-server-dom-* packages before 19.0 at all. The affected packages and versions are included in GHSA-fv66-9v8q-g76r.

Neither react nor react-dom packages are vulnerable.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These hasOwnProperty checks were the ones that were missing. This is the critical fix. Without it, you can drill into objects not created by the parser itself.

The rest is mainly protecting against other gadgets and to slow down reverse engineering just a bit (which seems to have been somewhat effective especially with llms).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this have also been solved by re-creating an object's own properties on a new object with a null prototype? If I'm not missing something, I imagine that would avoid the "shotgun surgery" of ensuring .hasOwnProperty guards anywhere which the object's properties are traversed.

}
}
const name = path[i];
if (typeof value === 'object' && hasOwnProperty.call(value, name)) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other one.

The ones on the module is not that critical but good to have.

@AlexDev404

Copy link
Copy Markdown

We did a number of refactors ...
This also fixes a critical security vulnerability.

With this combined commit, people now have to go through a >1500 line patch to try to understand the security relevant changes.

Going forward, it would be preferable if code changes for a critical security vulnerability could be committed separately from other changes. :-)

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

@jschauma

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

@AlexDev404

AlexDev404 commented Dec 6, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.

The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

@DogRespector93

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

@AlexDev404

AlexDev404 commented Dec 9, 2025

Copy link
Copy Markdown

It was disclosed to the React team since November 29, 2025--so it's something I'd say quite a few people have reviewed already--we're just seeing it now, because they most likely already coordinated what they're going to do.

That's not the point, though.
The issue here is that sliding in a security fix with a refactor makes it difficult for anybody to whom it has not yet been disclosed to understand the vulnerability, to develop their defenses, and for the historical record to be obscured. It is not uncommon for a vulnerability fix to be incomplete and later require additional follow-up, or for a future reference to a given code fix. This is all made more difficult here.

There was no "sliding" of any security fix. The person went through all of the steps of responsibly disclosing the vulnerability and it was released just as any other critical vulnerability. Haven't you been keeping yourself updated with the news? If not, I can for sure see why you'd say something like this.

If the concern is disclosure, then the vulnerability could be kept under embargo and patching be done with coordination (as was and still is being done, and which I appreciate), but lifting an embargo and then trying to keep the actual vulnerability obscured only leads to wasted cycles on the defenders' side (see also the large number of AI slopped "PoC"s and poorly understand speculation).

It's a CVE--the point of it is to go public. I don't think you understand. React is an open-source project, not proprietary. So secretly pushing in a patch and then telling everyone after would defeat the entire purpose of it being an open source project. Also how would you "propose" they do so with React being an NPM package and not a piece of software you can just update? To disclose or not disclose would be irrelevant, as anyone bright enough could easily find out what the changes were.

Vulnerability disclosure can be done in multiple stages, but when actual public disclosure is done, it's best to be specific and clear at that point.

The changes are very clean, and very minimal. IMO only someone who doesn't have a clue about how React works would say something like this. They've been very active in telling everyone essential about what's going on. So just because they didn't tell you to update your hobby project, doesn't give you the right to just come here and think you can get all like this.

Hey, for real, you do not have to be rude to someone asking polite, critical-thinking-oriented questions about how and why developers make certain choices in their project. It is not a status symbol to bully other coders doing "hobby projects" because you think it'll impress other devs. Your attitude makes the actual hardworking React teams look bad, not good. Your projects are easily just as "hobby" as theirs, and that's fine! You aren't managing some enterprise project- you're exploring - and anyone with experience doing it professionally knows attitudes like yours are caustic to progress.

I think you're misunderstanding, because I never said hobby project as if it was something bad. I assumed that that person created something using React for their own personal usage, and was upset by the fact that they never got notified about the issue. And so I think you're heavily inferring on something that wasn't the case.

They asked legitimate questions. You can say, "This isn't really the forum for these kinds of questions, and I don't actually know the answer, but here's a good place to ask: ", and no one will think any less of you.

They never asked any questions, and instead made targeted jabs as to what was happening. If they just made questions, this probably never would've happened.

See the attached thread for further context on their messages

@galqbineva27-collabgalqbineva27-collab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mattdanielbrown added a commit to mattdanielbrown/netlify-faunadb-example-todo-app that referenced this pull request Jan 14, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)
<h3>Snyk has created this PR to upgrade react from 16.14.0 to
19.2.3.</h3>
:information_source: Keep your dependencies up-to-date. This makes it
easier to fix existing vulnerabilities and to more quickly identify and
fix newly disclosed vulnerabilities when they affect your project.
<hr/>
- The recommended version is **1059 versions** ahead of your current
version.
- The recommended version was released **a month ago**.
<details>
<summary><b>Release notes</b></summary>
<br/>
<details>
<summary>Package name: <b>react</b></summary>
<ul>
<li>
<b>19.2.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.2.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3697023033" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard"
href="https://redirect.github.com/facebook/react/pull/35290">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.2.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.2.0</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.2.0">2025-10-01</a></br><p>Below
is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2025/10/01/react-19-2"
rel="nofollow">React 19.2 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><a href="https://react.dev/reference/react/Activity"
rel="nofollow"><code>&lt;Activity&gt;</code></a>: A new API to hide and
restore the UI and internal state of its children.</li>
<li><a href="https://react.dev/reference/react/useEffectEvent"
rel="nofollow"><code>useEffectEvent</code></a> is a React Hook that lets
you extract non-reactive logic into an <a
href="https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event"
rel="nofollow">Effect Event</a>.</li>
<li><a href="https://react.dev/reference/react/cacheSignal"
rel="nofollow"><code>cacheSignal</code></a> (for RSCs) lets your know
when the <code>cache()</code> lifetime is over.</li>
<li><a
href="https://react.dev/reference/developer-tooling/react-performance-tracks"
rel="nofollow">React Performance tracks</a> appear on the Performance
panel’s timeline in your browser developer tools</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li>Added resume APIs for partial pre-rendering with Web Streams:
<ul>
<li><a href="https://react.dev/reference/react-dom/server/resume"
rel="nofollow"><code>resume</code></a>: to resume a prerender to a
stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerender"
rel="nofollow"><code>resumeAndPrerender</code></a>: to resume a
prerender to HTML.</li>
</ul>
</li>
<li>Added resume APIs for partial pre-rendering with Node Streams:
<ul>
<li><a
href="https://react.dev/reference/react-dom/server/resumeToPipeableStream"
rel="nofollow"><code>resumeToPipeableStream</code></a>: to resume a
prerender to a stream.</li>
<li><a
href="https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream"
rel="nofollow"><code>resumeAndPrerenderToNodeStream</code></a>: to
resume a prerender to HTML.</li>
</ul>
</li>
<li>Updated <a
href="https://react.dev/reference/react-dom/static/prerender"
rel="nofollow"><code>prerender</code></a> APIs to return a
<code>postponed</code> state that can be passed to the
<code>resume</code> APIs.</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>React DOM now batches suspense boundary reveals, matching the
behavior of client side rendering. This change is especially noticeable
when animating the reveal of Suspense boundaries e.g. with the upcoming
<code>&lt;ViewTransition&gt;</code> Component. React will batch as much
reveals as possible before the first paint while trying to hit popular
first-contentful paint metrics.</li>
<li>Add Node Web Streams (<code>prerender</code>,
<code>renderToReadableStream</code>) to server-side-rendering APIs for
Node.js</li>
<li>Use underscore instead of <code>:</code> IDs generated by useId</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li><code>&lt;Activity /&gt;</code> was developed over many years,
starting before <code>ClassComponent.setState</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> and
many others)</li>
<li>Stringify context as "SomeContext" instead of "SomeContext.Provider"
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/kassens/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/kassens">@ kassens</a> <a
href="https://redirect.github.com/facebook/react/pull/33507"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33507/hovercard">#33507</a>)</li>
<li>Include stack of cause of React instrumentation errors with
<code>%o</code> placeholder (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34198"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34198/hovercard">#34198</a>)</li>
<li>Fix infinite <code>useDeferredValue</code> loop in popstate event
(<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/32821"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32821/hovercard">#32821</a>)</li>
<li>Fix a bug when an initial value was passed to
<code>useDeferredValue</code> (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/acdlite/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/acdlite">@ acdlite</a> <a
href="https://redirect.github.com/facebook/react/pull/34376"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34376/hovercard">#34376</a>)</li>
<li>Fix a crash when submitting forms with Client Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33055"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33055/hovercard">#33055</a>)</li>
<li>Hide/unhide the content of dehydrated suspense boundaries if they
resuspend (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32900"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32900/hovercard">#32900</a>)</li>
<li>Avoid stack overflow on wide trees during Hot Reload (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sophiebits/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sophiebits">@ sophiebits</a> <a
href="https://redirect.github.com/facebook/react/pull/34145"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34145/hovercard">#34145</a>)</li>
<li>Improve Owner and Component stacks in various places (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/33629"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33629/hovercard">#33629</a>, <a
href="https://redirect.github.com/facebook/react/pull/33724"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33724/hovercard">#33724</a>, <a
href="https://redirect.github.com/facebook/react/pull/32735"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32735/hovercard">#32735</a>, <a
href="https://redirect.github.com/facebook/react/pull/33723"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33723/hovercard">#33723</a>)</li>
<li>Add <code>cacheSignal</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33557"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33557/hovercard">#33557</a>)</li>
</ul>
<h3>React DOM</h3>
<ul>
<li>Block on Suspensey Fonts during reveal of server-side-rendered
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard">#33342</a>)</li>
<li>Use underscore instead of <code>:</code> for IDs generated by
<code>useId</code> (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a>: <a
href="https://redirect.github.com/facebook/react/pull/32001"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32001/hovercard">#32001</a>, <a
class="issue-link js-issue-link" data-error-text="Failed to load title"
data-id="3084407166" data-permission-text="Title is private"
data-url="https://github.com/facebook/react/issues/33342"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33342/hovercard"
href="https://redirect.github.com/facebook/react/pull/33342">#33342</a><a
href="https://redirect.github.com/facebook/react/pull/33099"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33099/hovercard">#33099</a>, <a
href="https://redirect.github.com/facebook/react/pull/33422"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33422/hovercard">#33422</a>)</li>
<li>Stop warning when ARIA 1.3 attributes are used (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Abdul-Omira/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Abdul-Omira">@ Abdul-Omira</a> <a
href="https://redirect.github.com/facebook/react/pull/34264"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34264/hovercard">#34264</a>)</li>
<li>Allow <code>nonce</code> to be used on hoistable styles (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/Andarist/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/Andarist">@ Andarist</a> <a
href="https://redirect.github.com/facebook/react/pull/32461"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32461/hovercard">#32461</a>)</li>
<li>Warn for using a React owned node as a Container if it also has text
content (<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/32774"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32774/hovercard">#32774</a>)</li>
<li>s/HTML/text for for error messages if text hydration mismatches (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/rickhanlonii/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/rickhanlonii">@ rickhanlonii</a> <a
href="https://redirect.github.com/facebook/react/pull/32763"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32763/hovercard">#32763</a>)</li>
<li>Fix a bug with <code>React.use</code> inside
<code>React.lazy</code>-ed Component (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hi-ogawa/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hi-ogawa">@ hi-ogawa</a> <a
href="https://redirect.github.com/facebook/react/pull/33941"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33941/hovercard">#33941</a>)</li>
<li>Enable the <code>progressiveChunkSize</code> option for
server-side-rendering APIs (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33027"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33027/hovercard">#33027</a>)</li>
<li>Fix a bug with deeply nested Suspense inside Suspense fallback when
server-side-rendering (<a class="user-mention notranslate"
data-hovercard-type="user" data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/33467"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33467/hovercard">#33467</a>)</li>
<li>Avoid hanging when suspending after aborting while rendering (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/gnoff/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/gnoff">@ gnoff</a> <a
href="https://redirect.github.com/facebook/react/pull/34192"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34192/hovercard">#34192</a>)</li>
<li>Add Node Web Streams to server-side-rendering APIs for Node.js (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33475"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33475/hovercard">#33475</a>)</li>
</ul>
<h3>React Server Components</h3>
<ul>
<li>Preload <code>&lt;img&gt;</code> and <code>&lt;link&gt;</code> using
hints before they're rendered (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34604"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34604/hovercard">#34604</a>)</li>
<li>Log error if production elements are rendered during development (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/34189"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34189/hovercard">#34189</a>)</li>
<li>Fix a bug when returning a Temporary reference (e.g. a Client
Reference) from Server Functions (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/34084"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34084/hovercard">#34084</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/denk0403/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/denk0403">@ denk0403</a> <a
href="https://redirect.github.com/facebook/react/pull/33761"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33761/hovercard">#33761</a>)</li>
<li>Pass line/column to <code>filterStackFrame</code> (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/33707"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33707/hovercard">#33707</a>)</li>
<li>Support Async Modules in Turbopack Server References (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/lubieowoce/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/lubieowoce">@ lubieowoce</a> <a
href="https://redirect.github.com/facebook/react/pull/34531"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34531/hovercard">#34531</a>)</li>
<li>Add support for .mjs file extension in Webpack (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/jennyscript/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/jennyscript">@ jennyscript</a> <a
href="https://redirect.github.com/facebook/react/pull/33028"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33028/hovercard">#33028</a>)</li>
<li>Fix a wrong missing key warning (<a class="user-mention notranslate"
data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/34350"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34350/hovercard">#34350</a>)</li>
<li>Make console log resolve in predictable order (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/33665"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33665/hovercard">#33665</a>)</li>
</ul>
<h3>React Reconciler</h3>
<ul>
<li><a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261">createContainer</a>
and <a
href="https://redirect.github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312">createHydrationContainer</a>
had their parameter order adjusted after <code>on*</code> handlers to
account for upcoming experimental APIs</li>
</ul>
<h2>eslint-plugin-react-hooks@6.1.0</h2>
<p><strong>Note:</strong> Version 6.0.0 was mistakenly released and
immediately deprecated and untagged on npm. This is the first official
6.x major release and includes breaking changes.</p>
<ul>
<li><strong>Breaking:</strong> Require Node.js 18 or newer. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32458"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32458/hovercard">#32458</a>)</li>
<li><strong>Breaking:</strong> Flat config is now the default
<code>recommended</code> preset. Legacy config moved to
<code>recommended-legacy</code>. (<a
href="https://redirect.github.com/michaelfaith">@ michaelfaith</a> in <a
href="https://redirect.github.com/facebook/react/pull/32457"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/32457/hovercard">#32457</a>)</li>
<li><strong>New Violations:</strong> Disallow calling <code>use</code>
within try/catch blocks. (<a href="https://redirect.github.com/poteto">@
poteto</a> in <a
href="https://redirect.github.com/facebook/react/pull/34040"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34040/hovercard">#34040</a>)</li>
<li><strong>New Violations:</strong> Disallow calling
<code>useEffectEvent</code> functions in arbitrary closures. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a> in <a
href="https://redirect.github.com/facebook/react/pull/33544"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33544/hovercard">#33544</a>)</li>
<li>Handle <code>React.useEffect</code> in addition to
<code>useEffect</code> in rules-of-hooks. (<a
href="https://redirect.github.com/Ayc0">@ Ayc0</a> in <a
href="https://redirect.github.com/facebook/react/pull/34076"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34076/hovercard">#34076</a>)</li>
<li>Added <code>react-hooks</code> settings config option that to accept
<code>additionalEffectHooks</code> that are used across exhaustive-deps
and rules-of-hooks rules. (<a
href="https://redirect.github.com/jbrown215">@ jbrown215</a>) in <a
href="https://redirect.github.com/facebook/react/pull/34497"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/34497/hovercard">#34497</a></li>
</ul>
</li>
<li>
<b>19.2.0-canary-fa3feba6-20250623</b> - 2025-06-23
</li>
<li>
<b>19.2.0-canary-f9ae0a4c-20250527</b> - 2025-05-27
</li>
<li>
<b>19.2.0-canary-f7396427-20250501</b> - 2025-05-02
</li>
<li>
<b>19.2.0-canary-f508edc8-20250818</b> - 2025-08-18
</li>
<li>
<b>19.2.0-canary-f3a80361-20250911</b> - 2025-09-11
</li>
<li>
<b>19.2.0-canary-f1e70b5e-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-f1222f76-20250812</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-ef8b6fa2-20250702</b> - 2025-07-03
</li>
<li>
<b>19.2.0-canary-ef889445-20250930</b> - 2025-09-30
</li>
<li>
<b>19.2.0-canary-edac0dde-20250723</b> - 2025-07-23
</li>
<li>
<b>19.2.0-canary-eaee5308-20250728</b> - 2025-07-28
</li>
<li>
<b>19.2.0-canary-ea05b750-20250408</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-e9db3cc2-20250501</b> - 2025-05-01
</li>
<li>
<b>19.2.0-canary-e9638c33-20250721</b> - 2025-07-21
</li>
<li>
<b>19.2.0-canary-e6dc25da-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-e5dd82a7-20250401</b> - 2025-04-01
</li>
<li>
<b>19.2.0-canary-e2332183-20250924</b> - 2025-09-24
</li>
<li>
<b>19.2.0-canary-dffacc7b-20250717</b> - 2025-07-17
</li>
<li>
<b>19.2.0-canary-df38ac9a-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-de5a1b20-20250905</b> - 2025-09-05
</li>
<li>
<b>19.2.0-canary-d92056ef-20250627</b> - 2025-06-27
</li>
<li>
<b>19.2.0-canary-d85f86cf-20250514</b> - 2025-05-14
</li>
<li>
<b>19.2.0-canary-d85ec5f5-20250716</b> - 2025-07-16
</li>
<li>
<b>19.2.0-canary-d415fd3e-20250919</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-d15d7fd7-20250929</b> - 2025-09-29
</li>
<li>
<b>19.2.0-canary-cee7939b-20250625</b> - 2025-06-25
</li>
<li>
<b>19.2.0-canary-c498bfce-20250426</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-c4676e72-20250520</b> - 2025-05-20
</li>
<li>
<b>19.2.0-canary-c44e4a25-20250409</b> - 2025-04-10
</li>
<li>
<b>19.2.0-canary-c260b38d-20250731</b> - 2025-07-31
</li>
<li>
<b>19.2.0-canary-c129c242-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-c0464aed-20250523</b> - 2025-05-26
</li>
<li>
<b>19.2.0-canary-befc1246-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-be11cb5c-20250804</b> - 2025-08-04
</li>
<li>
<b>19.2.0-canary-bdb4a96f-20250801</b> - 2025-08-01
</li>
<li>
<b>19.2.0-canary-bc6184dd-20250417</b> - 2025-04-18
</li>
<li>
<b>19.2.0-canary-bbc13fa1-20250624</b> - 2025-06-24
</li>
<li>
<b>19.2.0-canary-bb6f0c8d-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b9cfa0d3-20250505</b> - 2025-05-05
</li>
<li>
<b>19.2.0-canary-b9a04536-20250904</b> - 2025-09-04
</li>
<li>
<b>19.2.0-canary-b94603b9-20250513</b> - 2025-05-13
</li>
<li>
<b>19.2.0-canary-b7e2de63-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-b6c0aa88-20250609</b> - 2025-06-09
</li>
<li>
<b>19.2.0-canary-b4477d38-20250605</b> - 2025-06-05
</li>
<li>
<b>19.2.0-canary-b1b0955f-20250901</b> - 2025-09-01
</li>
<li>
<b>19.2.0-canary-b10cb4c0-20250403</b> - 2025-04-03
</li>
<li>
<b>19.2.0-canary-b0c1dc01-20250925</b> - 2025-09-25
</li>
<li>
<b>19.2.0-canary-b07717d8-20250528</b> - 2025-05-28
</li>
<li>
<b>19.2.0-canary-b04254fd-20250415</b> - 2025-04-16
</li>
<li>
<b>19.2.0-canary-ac7820a9-20250811</b> - 2025-08-11
</li>
<li>
<b>19.2.0-canary-ab859e31-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-aad7c664-20250829</b> - 2025-08-29
</li>
<li>
<b>19.2.0-canary-a96a0f39-20250815</b> - 2025-08-15
</li>
<li>
<b>19.2.0-canary-a7a11657-20250708</b> - 2025-07-08
</li>
<li>
<b>19.2.0-canary-a00ca6f6-20250611</b> - 2025-06-11
</li>
<li>
<b>19.2.0-canary-9be531cd-20250729</b> - 2025-07-29
</li>
<li>
<b>19.2.0-canary-99efc627-20250523</b> - 2025-05-23
</li>
<li>
<b>19.2.0-canary-97cdd5d3-20250710</b> - 2025-07-11
</li>
<li>
<b>19.2.0-canary-9784cb37-20250730</b> - 2025-07-30
</li>
<li>
<b>19.2.0-canary-96c61b7f-20250709</b> - 2025-07-10
</li>
<li>
<b>19.2.0-canary-93d7aa69-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-914319ae-20250423</b> - 2025-04-23
</li>
<li>
<b>19.2.0-canary-8e60cb7e-20250902</b> - 2025-09-02
</li>
<li>
<b>19.2.0-canary-8d7b5e49-20250827</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-8ce15b0f-20250522</b> - 2025-05-22
</li>
<li>
<b>19.2.0-canary-8bb7241f-20250926</b> - 2025-09-26
</li>
<li>
<b>19.2.0-canary-8a8e9a7e-20250912</b> - 2025-09-12
</li>
<li>
<b>19.2.0-canary-89a803fc-20250828</b> - 2025-08-28
</li>
<li>
<b>19.2.0-canary-886b3d36-20250910</b> - 2025-09-10
</li>
<li>
<b>19.2.0-canary-873f7112-20250821</b> - 2025-08-21
</li>
<li>
<b>19.2.0-canary-86181134-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-84af9085-20250917</b> - 2025-09-18
</li>
<li>
<b>19.2.0-canary-83c88ad4-20250923</b> - 2025-09-23
</li>
<li>
<b>19.2.0-canary-7deda941-20250804</b> - 2025-08-05
</li>
<li>
<b>19.2.0-canary-7a2c7045-20250506</b> - 2025-05-06
</li>
<li>
<b>19.2.0-canary-79d9aed7-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-7513996f-20250722</b> - 2025-07-22
</li>
<li>
<b>19.2.0-canary-73aa744b-20250702</b> - 2025-07-02
</li>
<li>
<b>19.2.0-canary-7216c0f0-20250630</b> - 2025-07-01
</li>
<li>
<b>19.2.0-canary-72135096-20250421</b> - 2025-04-22
</li>
<li>
<b>19.2.0-canary-6eda5347-20250918</b> - 2025-09-19
</li>
<li>
<b>19.2.0-canary-6de32a5a-20250822</b> - 2025-08-22
</li>
<li>
<b>19.2.0-canary-6b70072c-20250909</b> - 2025-09-09
</li>
<li>
<b>19.2.0-canary-6a7650c7-20250405</b> - 2025-04-05
</li>
<li>
<b>19.2.0-canary-67a44bcd-20250915</b> - 2025-09-15
</li>
<li>
<b>19.2.0-canary-66f09bd0-20250806</b> - 2025-08-06
</li>
<li>
<b>19.2.0-canary-65c4decb-20250630</b> - 2025-06-30
</li>
<li>
<b>19.2.0-canary-63779030-20250328</b> - 2025-03-31
</li>
<li>
<b>19.2.0-canary-60b5271a-20250709</b> - 2025-07-09
</li>
<li>
<b>19.2.0-canary-5e0c951b-20250916</b> - 2025-09-16
</li>
<li>
<b>19.2.0-canary-5dc00d6b-20250428</b> - 2025-04-28
</li>
<li>
<b>19.2.0-canary-5d87cd22-20250704</b> - 2025-07-04
</li>
<li>
<b>19.2.0-canary-56408a5b-20250610</b> - 2025-06-10
</li>
<li>
<b>19.2.0-canary-548235db-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-540cd652-20250403</b> - 2025-04-04
</li>
<li>
<b>19.2.0-canary-534bed5f-20250813</b> - 2025-08-13
</li>
<li>
<b>19.2.0-canary-526dd340-20250602</b> - 2025-06-02
</li>
<li>
<b>19.2.0-canary-4db4b21c-20250626</b> - 2025-06-26
</li>
<li>
<b>19.2.0-canary-4a45ba92-20250515</b> - 2025-05-15
</li>
<li>
<b>19.2.0-canary-4a36d3ea-20250416</b> - 2025-04-17
</li>
<li>
<b>19.2.0-canary-462d08f9-20250517</b> - 2025-05-19
</li>
<li>
<b>19.2.0-canary-4448b187-20250515</b> - 2025-05-16
</li>
<li>
<b>19.2.0-canary-4123f6b7-20250826</b> - 2025-08-26
</li>
<li>
<b>19.2.0-canary-408d055a-20250430</b> - 2025-04-30
</li>
<li>
<b>19.2.0-canary-3fbfb9ba-20250409</b> - 2025-04-09
</li>
<li>
<b>19.2.0-canary-3fb190f7-20250908</b> - 2025-09-08
</li>
<li>
<b>19.2.0-canary-3d14fcf0-20250724</b> - 2025-07-24
</li>
<li>
<b>19.2.0-canary-39cad7af-20250411</b> - 2025-04-14
</li>
<li>
<b>19.2.0-canary-3958d5d8-20250807</b> - 2025-08-07
</li>
<li>
<b>19.2.0-canary-38ef6550-20250508</b> - 2025-05-08
</li>
<li>
<b>19.2.0-canary-3820740a-20250509</b> - 2025-05-12
</li>
<li>
<b>19.2.0-canary-379a083b-20250813</b> - 2025-08-14
</li>
<li>
<b>19.2.0-canary-37054867-20250604</b> - 2025-06-04
</li>
<li>
<b>19.2.0-canary-33a1095d-20250827</b> - 2025-08-27
</li>
<li>
<b>19.2.0-canary-33661467-20250407</b> - 2025-04-07
</li>
<li>
<b>19.2.0-canary-3302d1f7-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-2f0e7e57-20250715</b> - 2025-07-15
</li>
<li>
<b>19.2.0-canary-280ff6fe-20250606</b> - 2025-06-06
</li>
<li>
<b>19.2.0-canary-2805f0ed-20250903</b> - 2025-09-03
</li>
<li>
<b>19.2.0-canary-23884812-20250520</b> - 2025-05-21
</li>
<li>
<b>19.2.0-canary-223f81d8-20250707</b> - 2025-07-07
</li>
<li>
<b>19.2.0-canary-21fdf308-20250508</b> - 2025-05-09
</li>
<li>
<b>19.2.0-canary-1eca9a27-20250922</b> - 2025-09-22
</li>
<li>
<b>19.2.0-canary-1dc3bdea-20250812</b> - 2025-08-12
</li>
<li>
<b>19.2.0-canary-1d6c8168-20250411</b> - 2025-04-11
</li>
<li>
<b>19.2.0-canary-1bd1f01f-20251001</b> - 2025-10-01
</li>
<li>
<b>19.2.0-canary-1ae0a845-20250603</b> - 2025-06-03
</li>
<li>
<b>19.2.0-canary-19baee81-20250725</b> - 2025-07-25
</li>
<li>
<b>19.2.0-canary-197d6a04-20250424</b> - 2025-04-24
</li>
<li>
<b>19.2.0-canary-143d3e1b-20250425</b> - 2025-04-25
</li>
<li>
<b>19.2.0-canary-14094f80-20250529</b> - 2025-05-29
</li>
<li>
<b>19.2.0-canary-12bc60f5-20250613</b> - 2025-06-13
</li>
<li>
<b>19.2.0-canary-128abcfa-20250917</b> - 2025-09-17
</li>
<li>
<b>19.2.0-canary-0ff1d13b-20250507</b> - 2025-05-07
</li>
<li>
<b>19.2.0-canary-0bdb9206-20250818</b> - 2025-08-19
</li>
<li>
<b>19.2.0-canary-06e89951-20250620</b> - 2025-06-20
</li>
<li>
<b>19.2.0-canary-040f8286-20250402</b> - 2025-04-02
</li>
<li>
<b>19.2.0-canary-03fda05d-20250820</b> - 2025-08-20
</li>
<li>
<b>19.2.0-canary-0038c501-20250429</b> - 2025-04-29
</li>
<li>
<b>19.1.4</b> - 2025-12-11
</li>
<li>
<b>19.1.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Move <code>react-server-dom-webpack/*.unbundled</code> to private
<code>react-server-dom-unbundled</code> (<a class="user-mention
notranslate" data-hovercard-type="user"
data-hovercard-url="/users/eps1lon/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/eps1lon">@ eps1lon</a> <a
href="https://redirect.github.com/facebook/react/pull/35290"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35290/hovercard">#35290</a>)</li>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.1.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.2">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.1.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.1.1">2025-07-28</a></br><h3>React</h3>
<ul>
<li>Fixed Owner Stacks to work with ES2015 function.name semantics (<a
href="https://redirect.github.com/facebook/react/pull/33680"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/33680/hovercard">#33680</a> by
<a class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/hoxyq/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/hoxyq">@ hoxyq</a>)</li>
</ul>
</li>
<li>
<b>19.1.0</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ff628334-20250205</b> - 2025-02-06
</li>
<li>
<b>19.1.0-canary-fcb4e0f1-20250219</b> - 2025-02-20
</li>
<li>
<b>19.1.0-canary-fc8a898d-20241226</b> - 2024-12-27
</li>
<li>
<b>19.1.0-canary-fbcda19a-20250317</b> - 2025-03-17
</li>
<li>
<b>19.1.0-canary-f9d78089-20250306</b> - 2025-03-07
</li>
<li>
<b>19.1.0-canary-f83903bf-20250212</b> - 2025-02-12
</li>
<li>
<b>19.1.0-canary-f457d0b4-20250313</b> - 2025-03-13
</li>
<li>
<b>19.1.0-canary-f0edf41e-20250115</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-ef979d47-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-ef4bc8b4-20250328</b> - 2025-03-28
</li>
<li>
<b>19.1.0-canary-ebc22ef7-20250225</b> - 2025-02-26
</li>
<li>
<b>19.1.0-canary-e670e72f-20250214</b> - 2025-02-14
</li>
<li>
<b>19.1.0-canary-e1e74071-20250321</b> - 2025-03-21
</li>
<li>
<b>19.1.0-canary-e06c72fc-20241215</b> - 2024-12-16
</li>
<li>
<b>19.1.0-canary-e03ac20f-20250305</b> - 2025-03-05
</li>
<li>
<b>19.1.0-canary-de82912e-20241220</b> - 2024-12-20
</li>
<li>
<b>19.1.0-canary-de1eaa26-20250124</b> - 2025-01-24
</li>
<li>
<b>19.1.0-canary-db7dfe05-20250319</b> - 2025-03-19
</li>
<li>
<b>19.1.0-canary-d85cf3e5-20250205</b> - 2025-02-05
</li>
<li>
<b>19.1.0-canary-d55cc79b-20250228</b> - 2025-02-28
</li>
<li>
<b>19.1.0-canary-d46b04a2-20250117</b> - 2025-01-17
</li>
<li>
<b>19.1.0-canary-d4287258-20241217</b> - 2024-12-17
</li>
<li>
<b>19.1.0-canary-d331ba04-20250307</b> - 2025-03-10
</li>
<li>
<b>19.1.0-canary-cd90a4d8-20250210</b> - 2025-02-11
</li>
<li>
<b>19.1.0-canary-cbbe8666-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-cabd8a0e-20250113</b> - 2025-01-13
</li>
<li>
<b>19.1.0-canary-c69a5fc5-20250318</b> - 2025-03-18
</li>
<li>
<b>19.1.0-canary-c492f975-20250128</b> - 2025-01-29
</li>
<li>
<b>19.1.0-canary-c01b8058-20241229</b> - 2024-12-30
</li>
<li>
<b>19.1.0-canary-bb9a24d9-20250130</b> - 2025-01-30
</li>
<li>
<b>19.1.0-canary-b3a95caf-20250113</b> - 2025-01-14
</li>
<li>
<b>19.1.0-canary-b158439a-20250115</b> - 2025-01-15
</li>
<li>
<b>19.1.0-canary-ae9017ce-20250122</b> - 2025-01-23
</li>
<li>
<b>19.1.0-canary-a84862db-20250218</b> - 2025-02-19
</li>
<li>
<b>19.1.0-canary-a4f9bd58-20250319</b> - 2025-03-20
</li>
<li>
<b>19.1.0-canary-a4b2d0d5-20250203</b> - 2025-02-03
</li>
<li>
<b>19.1.0-canary-9ff42a87-20250130</b> - 2025-01-31
</li>
<li>
<b>19.1.0-canary-9eabb373-20250124</b> - 2025-01-27
</li>
<li>
<b>19.1.0-canary-9b62ee71-20250122</b> - 2025-01-22
</li>
<li>
<b>19.1.0-canary-97d79495-20241223</b> - 2024-12-24
</li>
<li>
<b>19.1.0-canary-9463d51e-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-93b58361-20250209</b> - 2025-02-10
</li>
<li>
<b>19.1.0-canary-8a7b487e-20250218</b> - 2025-02-18
</li>
<li>
<b>19.1.0-canary-8759c5c8-20250207</b> - 2025-02-07
</li>
<li>
<b>19.1.0-canary-7eb8234f-20241218</b> - 2024-12-18
</li>
<li>
<b>19.1.0-canary-7b402084-20250107</b> - 2025-01-07
</li>
<li>
<b>19.1.0-canary-74ea0c73-20250109</b> - 2025-01-09
</li>
<li>
<b>19.1.0-canary-740a4f7a-20250325</b> - 2025-03-25
</li>
<li>
<b>19.1.0-canary-7130d0c6-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-6aa8254b-20250312</b> - 2025-03-12
</li>
<li>
<b>19.1.0-canary-694d3e1a-20241231</b> - 2025-01-01
</li>
<li>
<b>19.1.0-canary-6907aa2a-20241220</b> - 2024-12-23
</li>
<li>
<b>19.1.0-canary-662957cc-20250221</b> - 2025-02-21
</li>
<li>
<b>19.1.0-canary-62208bee-20250102</b> - 2025-01-02
</li>
<li>
<b>19.1.0-canary-5b51a2b9-20250116</b> - 2025-01-16
</li>
<li>
<b>19.1.0-canary-540efebc-20250112</b> - 2025-01-12
</li>
<li>
<b>19.1.0-canary-5398b711-20250314</b> - 2025-03-14
</li>
<li>
<b>19.1.0-canary-518d06d2-20241219</b> - 2024-12-19
</li>
<li>
<b>19.1.0-canary-4dff0e62-20241213</b> - 2024-12-13
</li>
<li>
<b>19.1.0-canary-4632e36a-20250216</b> - 2025-02-17
</li>
<li>
<b>19.1.0-canary-443b7ff2-20250303</b> - 2025-03-04
</li>
<li>
<b>19.1.0-canary-4280563b-20250326</b> - 2025-03-27
</li>
<li>
<b>19.1.0-canary-42687267-20250108</b> - 2025-01-08
</li>
<li>
<b>19.1.0-canary-3ce77d55-20250106</b> - 2025-01-06
</li>
<li>
<b>19.1.0-canary-3b009b4c-20250102</b> - 2025-01-03
</li>
<li>
<b>19.1.0-canary-37906d4d-20250127</b> - 2025-01-28
</li>
<li>
<b>19.1.0-canary-32b0cad8-20250213</b> - 2025-02-13
</li>
<li>
<b>19.1.0-canary-313332d1-20250326</b> - 2025-03-26
</li>
<li>
<b>19.1.0-canary-2980f277-20250301</b> - 2025-03-03
</li>
<li>
<b>19.1.0-canary-25677265-20250224</b> - 2025-02-24
</li>
<li>
<b>19.1.0-canary-22e39ea7-20250225</b> - 2025-02-25
</li>
<li>
<b>19.1.0-canary-18eaf51b-20250118</b> - 2025-01-20
</li>
<li>
<b>19.1.0-canary-130095f7-20241212</b> - 2024-12-12
</li>
<li>
<b>19.1.0-canary-0ca3deeb-20250311</b> - 2025-03-11
</li>
<li>
<b>19.1.0-canary-0a82580b-20250203</b> - 2025-02-04
</li>
<li>
<b>19.1.0-canary-056073de-20250109</b> - 2025-01-10
</li>
<li>
<b>19.1.0-canary-029e8bd6-20250306</b> - 2025-03-06
</li>
<li>
<b>19.0.3</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.3">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35351"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35351/hovercard">#35351</a>)</li>
</ul>
</li>
<li>
<b>19.0.2</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.2">2025-12-11</a></br><h2>React
Server Components</h2>
<ul>
<li>Patch Promise cycles and toString on Server Functions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a>, <a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/unstubbable/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/unstubbable">@ unstubbable</a> <a
href="https://redirect.github.com/facebook/react/pull/35289"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35289/hovercard">#35289</a>, <a
href="https://redirect.github.com/facebook/react/pull/35345"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35345/hovercard">#35345</a>)</li>
</ul>
</li>
<li>
<b>19.0.1</b> - <a
href="https://redirect.github.com/facebook/react/releases/tag/v19.0.1">2025-12-03</a></br><h2>React
Server Components</h2>
<ul>
<li>Bring React Server Component fixes to Server Actions (<a
class="user-mention notranslate" data-hovercard-type="user"
data-hovercard-url="/users/sebmarkbage/hovercard"
data-octo-click="hovercard-link-click"
data-octo-dimensions="link_type:self"
href="https://redirect.github.com/sebmarkbage">@ sebmarkbage</a> <a
href="https://redirect.github.com/facebook/react/pull/35277"
data-hovercard-type="pull_request"
data-hovercard-url="/facebook/react/pull/35277/hovercard">#35277</a>)</li>
</ul>
</li>
<li>
<b>19.0.0</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-fb9a90fa48-20240614</b> - 2024-06-14
</li>
<li>
<b>19.0.0-rc-fa6eab58-20240815</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-f9ebd85a-20240925</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-f994737d14-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-f90a6bcc-20240827</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f6cce072-20240723</b> - 2024-07-23
</li>
<li>
<b>19.0.0-rc-f65ac7bd-20240826</b> - 2024-08-27
</li>
<li>
<b>19.0.0-rc-f3e09d6328-20240612</b> - 2024-06-12
</li>
<li>
<b>19.0.0-rc-f38c22b244-20240704</b> - 2024-07-05
</li>
<li>
<b>19.0.0-rc-f2df5694-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ee1a403a-20240916</b> - 2024-09-16
</li>
<li>
<b>19.0.0-rc-ed966dac-20241007</b> - 2024-10-08
</li>
<li>
<b>19.0.0-rc-ed15d500-20241110</b> - 2024-11-11
</li>
<li>
<b>19.0.0-rc-eb3ad065-20240822</b> - 2024-08-22
</li>
<li>
<b>19.0.0-rc-eb259b5d3b-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-e948a5ac-20240807</b> - 2024-08-07
</li>
<li>
<b>19.0.0-rc-e740d4b1-20240919</b> - 2024-09-19
</li>
<li>
<b>19.0.0-rc-e684ca66ab-20240619</b> - 2024-06-19
</li>
<li>
<b>19.0.0-rc-e56f4ae3-20240830</b> - 2024-08-30
</li>
<li>
<b>19.0.0-rc-e4953922-20240919</b> - 2024-09-20
</li>
<li>
<b>19.0.0-rc-e210d081-20240909</b> - 2024-09-09
</li>
<li>
<b>19.0.0-rc-e1ef8c95-20241115</b> - 2024-11-15
</li>
<li>
<b>19.0.0-rc-e02baf6c92-20240627</b> - 2024-06-27
</li>
<li>
<b>19.0.0-rc-dfd30974ab-20240613</b> - 2024-06-13
</li>
<li>
<b>19.0.0-rc-df783f9ea1-20240708</b> - 2024-07-08
</li>
<li>
<b>19.0.0-rc-df5f2736-20240712</b> - 2024-07-12
</li>
<li>
<b>19.0.0-rc-de68d2f4-20241204</b> - 2024-12-04
</li>
<li>
<b>19.0.0-rc-d8c90fa4-20241001</b> - 2024-10-01
</li>
<li>
<b>19.0.0-rc-d6cb4e77-20240911</b> - 2024-09-11
</li>
<li>
<b>19.0.0-rc-d5bba18b-20241009</b> - 2024-10-09
</li>
<li>
<b>19.0.0-rc-d49123f7-20241019</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-d48603a5-20240813</b> - 2024-08-13
</li>
<li>
<b>19.0.0-rc-d3ce0d3ea9-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-d1afcb43-20240903</b> - 2024-09-04
</li>
<li>
<b>19.0.0-rc-d025ddd3-20240722</b> - 2024-07-22
</li>
<li>
<b>19.0.0-rc-cd22717c-20241013</b> - 2024-10-13
</li>
<li>
<b>19.0.0-rc-cc1ec60d0d-20240607</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-cae764ce-20241025</b> - 2024-10-25
</li>
<li>
<b>19.0.0-rc-ca587425-20241211</b> - 2024-12-12
</li>
<li>
<b>19.0.0-rc-c3cdbec0a7-20240708</b> - 2024-07-09
</li>
<li>
<b>19.0.0-rc-c21bcd627b-20240624</b> - 2024-06-24
</li>
<li>
<b>19.0.0-rc-c1e1358b-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-c11c9510-20241120</b> - 2024-11-21
</li>
<li>
<b>19.0.0-rc-bf7e210c-20241017</b> - 2024-10-17
</li>
<li>
<b>19.0.0-rc-bf3a29d097-20240603</b> - 2024-06-04
</li>
<li>
<b>19.0.0-rc-b8ae38f8-20241018</b> - 2024-10-18
</li>
<li>
<b>19.0.0-rc-b7e21579-20241031</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-b57d2823-20240822</b> - 2024-08-23
</li>
<li>
<b>19.0.0-rc-b01722d5-20241114</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-ab7c1663-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-ab2135c7-20240724</b> - 2024-07-24
</li>
<li>
<b>19.0.0-rc-a99d8e8d-20240916</b> - 2024-09-17
</li>
<li>
<b>19.0.0-rc-a960b92c-20240819</b> - 2024-08-20
</li>
<li>
<b>19.0.0-rc-a7d1240c-20240731</b> - 2024-07-31
</li>
<li>
<b>19.0.0-rc-a532d91d01-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-a26e3f403e-20240611</b> - 2024-06-11
</li>
<li>
<b>19.0.0-rc-a19a8ab4-20240829</b> - 2024-08-29
</li>
<li>
<b>19.0.0-rc-a03254bc-20240905</b> - 2024-09-06
</li>
<li>
<b>19.0.0-rc-9d4fba0788-20240530</b> - 2024-05-30
</li>
<li>
<b>19.0.0-rc-9d2da591-20240808</b> - 2024-08-08
</li>
<li>
<b>19.0.0-rc-9c6806964f-20240703</b> - 2024-07-03
</li>
<li>
<b>19.0.0-rc-99da76f23a-20240606</b> - 2024-06-06
</li>
<li>
<b>19.0.0-rc-9598c41a20-20240603</b> - 2024-06-03
</li>
<li>
<b>19.0.0-rc-94e652d5-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-941e1b4a-20240729</b> - 2024-07-29
</li>
<li>
<b>19.0.0-rc-935180c7e0-20240524</b> - 2024-05-24
</li>
<li>
<b>19.0.0-rc-915b914b3a-20240515</b> - 2024-05-15
</li>
<li>
<b>19.0.0-rc-91061073-20241121</b> - 2024-11-22
</li>
<li>
<b>19.0.0-rc-8f3c0525f9-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-8b08e99e-20240713</b> - 2024-07-15
</li>
<li>
<b>19.0.0-rc-8971381549-20240625</b> - 2024-06-25
</li>
<li>
<b>19.0.0-rc-85acf2d195-20240711</b> - 2024-07-11
</li>
<li>
<b>19.0.0-rc-83825814-20241015</b> - 2024-10-15
</li>
<li>
<b>19.0.0-rc-827cbea417-20240606</b> - 2024-06-07
</li>
<li>
<b>19.0.0-rc-8269d55d-20240802</b> - 2024-08-02
</li>
<li>
<b>19.0.0-rc-81c5ff2e04-20240521</b> - 2024-05-21
</li>
<li>
<b>19.0.0-rc-7c8e5e7a-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-7ac8e612-20241113</b> - 2024-11-13
</li>
<li>
<b>19.0.0-rc-79ddf5b5-20241210</b> - 2024-12-11
</li>
<li>
<b>19.0.0-rc-77f43893-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-77b637d6-20241016</b> - 2024-10-16
</li>
<li>
<b>19.0.0-rc-778e1ed2-20240926</b> - 2024-09-25
</li>
<li>
<b>19.0.0-rc-7771d3a7-20240827</b> - 2024-08-28
</li>
<li>
<b>19.0.0-rc-7670501b-20241124</b> - 2024-11-25
</li>
<li>
<b>19.0.0-rc-76002254-20240724</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-7283a213-20241206</b> - 2024-12-06
</li>
<li>
<b>19.0.0-rc-70fb1363-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-6fb39ec9e9-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-6f23540c7d-20240528</b> - 2024-05-28
</li>
<li>
<b>19.0.0-rc-6f0dc294-20241119</b> - 2024-11-19
</li>
<li>
<b>19.0.0-rc-6ebfd5b0-20240818</b> - 2024-08-19
</li>
<li>
<b>19.0.0-rc-6d3110b4d9-20240531</b> - 2024-05-31
</li>
<li>
<b>19.0.0-rc-6cf85185-20241014</b> - 2024-10-14
</li>
<li>
<b>19.0.0-rc-69d4b800-20241021</b> - 2024-10-21
</li>
<li>
<b>19.0.0-rc-68dbd84b-20240812</b> - 2024-08-12
</li>
<li>
<b>19.0.0-rc-67fee58b-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-66855b96-20241106</b> - 2024-11-06
</li>
<li>
<b>19.0.0-rc-65e06cb7-20241218</b> - 2024-12-19
</li>
<li>
<b>19.0.0-rc-65a56d0e-20241020</b> - 2024-10-20
</li>
<li>
<b>19.0.0-rc-65903583-20240805</b> - 2024-08-05
</li>
<li>
<b>19.0.0-rc-64f89510-20241119</b> - 2024-11-20
</li>
<li>
<b>19.0.0-rc-6230622a1a-20240610</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-603e6108-20241029</b> - 2024-10-30
</li>
<li>
<b>19.0.0-rc-5dcb0097-20240918</b> - 2024-09-18
</li>
<li>
<b>19.0.0-rc-5d19e1c8-20240923</b> - 2024-09-23
</li>
<li>
<b>19.0.0-rc-5c56b873-20241107</b> - 2024-11-07
</li>
<li>
<b>19.0.0-rc-5b0ef217-20241202</b> - 2024-12-02
</li>
<li>
<b>19.0.0-rc-58af67a8f8-20240628</b> - 2024-06-28
</li>
<li>
<b>19.0.0-rc-57fbe3ba37-20240520</b> - 2024-05-20
</li>
<li>
<b>19.0.0-rc-512b09b2-20240718</b> - 2024-07-18
</li>
<li>
<b>19.0.0-rc-4f604941-20240830</b> - 2024-09-02
</li>
<li>
<b>19.0.0-rc-4d577fd2-20241104</b> - 2024-11-04
</li>
<li>
<b>19.0.0-rc-4c58fce7-20240904</b> - 2024-09-05
</li>
<li>
<b>19.0.0-rc-4c2e457c7c-20240522</b> - 2024-05-23
</li>
<li>
<b>19.0.0-rc-4beb1fd8-20241118</b> - 2024-11-18
</li>
<li>
<b>19.0.0-rc-4b7d4530-20241218</b> - 2024-12-18
</li>
<li>
<b>19.0.0-rc-49496d49-20240814</b> - 2024-08-14
</li>
<li>
<b>19.0.0-rc-47352209-20240912</b> - 2024-09-12
</li>
<li>
<b>19.0.0-rc-459fd418-20241001</b> - 2024-10-02
</li>
<li>
<b>19.0.0-rc-45804af1-20241021</b> - 2024-10-22
</li>
<li>
<b>19.0.0-rc-3f1436cca1-20240516</b> - 2024-05-17
</li>
<li>
<b>19.0.0-rc-3edc000d-20240926</b> - 2024-09-27
</li>
<li>
<b>19.0.0-rc-3dfd5d9e-20240910</b> - 2024-09-10
</li>
<li>
<b>19.0.0-rc-3da26163a3-20240704</b> - 2024-07-04
</li>
<li>
<b>19.0.0-rc-3ac551e855-20240522</b> - 2024-05-22
</li>
<li>
<b>19.0.0-rc-38e3b23483-20240529</b> - 2024-05-29
</li>
<li>
<b>19.0.0-rc-38af456a-20241010</b> - 2024-10-10
</li>
<li>
<b>19.0.0-rc-380f5d67-20241113</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc-378b305958-20240710</b> - 2024-07-10
</li>
<li>
<b>19.0.0-rc-372ec00c-20241209</b> - 2024-12-10
</li>
<li>
<b>19.0.0-rc-3563387fe3-20240621</b> - 2024-06-21
</li>
<li>
<b>19.0.0-rc-34d0c5e357-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-33c7bd9a-20241104</b> - 2024-11-05
</li>
<li>
<b>19.0.0-rc-3208e73e-20240730</b> - 2024-07-30
</li>
<li>
<b>19.0.0-rc-2ec26bc4-20241111</b> - 2024-11-12
</li>
<li>
<b>19.0.0-rc-2d2cc042-20240809</b> - 2024-08-09
</li>
<li>
<b>19.0.0-rc-2d16326d-20240930</b> - 2024-09-30
</li>
<li>
<b>19.0.0-rc-28668d39-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-20b6f4c0e8-20240607</b> - 2024-06-10
</li>
<li>
<b>19.0.0-rc-206df66e-20240912</b> - 2024-09-13
</li>
<li>
<b>19.0.0-rc-204a551e-20240926</b> - 2024-09-26
</li>
<li>
<b>19.0.0-rc-1eaccd82-20240816</b> - 2024-08-16
</li>
<li>
<b>19.0.0-rc-1df34bdf62-20240605</b> - 2024-06-05
</li>
<li>
<b>19.0.0-rc-1d989965-20240821</b> - 2024-08-21
</li>
<li>
<b>19.0.0-rc-1c9b1387-20241204</b> - 2024-12-05
</li>
<li>
<b>19.0.0-rc-1b1283ad-20241203</b> - 2024-12-03
</li>
<li>
<b>19.0.0-rc-19bd26be-20240815</b> - 2024-08-15
</li>
<li>
<b>19.0.0-rc-187dd6a7-20240806</b> - 2024-08-06
</li>
<li>
<b>19.0.0-rc-16409d05-20241101</b> - 2024-11-01
</li>
<li>
<b>19.0.0-rc-163365a0-20240717</b> - 2024-07-17
</li>
<li>
<b>19.0.0-rc-1631855f-20241023</b> - 2024-10-23
</li>
<li>
<b>19.0.0-rc-14a4699f-20240725</b> - 2024-07-25
</li>
<li>
<b>19.0.0-rc-1460d67c-20241003</b> - 2024-10-04
</li>
<li>
<b>19.0.0-rc-1434af3d22-20240618</b> - 2024-06-18
</li>
<li>
<b>19.0.0-rc-107a2f8c3e-20240617</b> - 2024-06-17
</li>
<li>
<b>19.0.0-rc-100dfd7dab-20240701</b> - 2024-07-01
</li>
<li>
<b>19.0.0-rc-0bc30748-20241028</b> - 2024-10-29
</li>
<li>
<b>19.0.0-rc-09111202-20241011</b> - 2024-10-11
</li>
<li>
<b>19.0.0-rc-0751fac7-20241002</b> - 2024-10-03
</li>
<li>
<b>19.0.0-rc-06d0b89e-20240801</b> - 2024-08-01
</li>
<li>
<b>19.0.0-rc-04bd67a4-20240924</b> - 2024-09-24
</li>
<li>
<b>19.0.0-rc-02c0e824-20241028</b> - 2024-10-28
</li>
<li>
<b>19.0.0-rc-01172397-20240716</b> - 2024-07-16
</li>
<li>
<b>19.0.0-rc.1</b> - 2024-11-14
</li>
<li>
<b>19.0.0-rc.0</b> - 2024-06-03
</li>
<li>
<b>19.0.0-canary-fd0da3eef-20240404</b> - 2024-04-04
</li>
<li>
<b>19.0.0-canary-e3ebcd54b-20240405</b> - 2024-04-05
</li>
<li>
<b>19.0.0-canary-db913d8e17-20240422</b> - 2024-04-22
</li>
<li>
<b>19.0.0-canary-cf5ab8b8b2-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-canary-cb151849e1-20240424</b> - 2024-04-24
</li>
<li>
<b>19.0.0-canary-adb717393-20240411</b> - 2024-04-11
</li>
<li>
<b>19.0.0-canary-a73c3450e-20240329</b> - 2024-03-29
</li>
<li>
<b>19.0.0-canary-96c584661-20240412</b> - 2024-04-12
</li>
<li>
<b>19.0.0-canary-95e6f032c-20240401</b> - 2024-04-01
</li>
<li>
<b>19.0.0-canary-8afa144bd-20240416</b> - 2024-04-16
</li>
<li>
<b>19.0.0-canary-7a2609eed-20240403</b> - 2024-04-03
</li>
<li>
<b>19.0.0-canary-657428a9e-20240416</b> - 2024-04-17
</li>
<li>
<b>19.0.0-canary-4c12339ce-20240408</b> - 2024-04-08
</li>
<li>
<b>19.0.0-canary-48ec17b86-20240402</b> - 2024-04-02
</li>
<li>
<b>19.0.0-canary-36e62c603-20240418</b> - 2024-04-18
</li>
<li>
<b>19.0.0-canary-33a32441e9-20240418</b> - 2024-04-19
</li>
<li>
<b>19.0.0-canary-2b036d3f1-20240327</b> - 2024-03-27
</li>
<li>
<b>19.0.0-canary-05797cceb-20240328</b> - 2024-03-28
</li>
<li>
<b>19.0.0-beta-e7d213dfb0-20240507</b> - 2024-05-07
</li>
<li>
<b>19.0.0-beta-b498834eab-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-9d76c954cf-20240510</b> - 2024-05-13
</li>
<li>
<b>19.0.0-beta-94eed63c49-20240425</b> - 2024-04-25
</li>
<li>
<b>19.0.0-beta-73bcdfbae5-20240502</b> - 2024-05-02
</li>
<li>
<b>19.0.0-beta-6946ebe620-20240508</b> - 2024-05-08
</li>
<li>
<b>19.0.0-beta-5d29478716-20240506</b> - 2024-05-06
</li>
<li>
<b>19.0.0-beta-4508873393-20240430</b> - 2024-04-30
</li>
<li>
<b>19.0.0-beta-26f2496093-20240514</b> - 2024-05-14
</li>
<li>
<b>19.0.0-beta-1beb73de0f-20240503</b> - 2024-05-03
</li>
<li>
<b>19.0.0-beta-04b058868c-20240508</b> - 2024-05-09
</li>
<li>
<b>18.3.1</b> - 2024-04-26
</li>
<li>
<b>18.3.0</b> - 2024-04-25
...
imdreamrunner added a commit to imdreamrunner/react that referenced this pull request Jun 23, 2026
ReactFlightClientConfigBundlerFB.js was missing the Server Reference
resolution guards the other bundlers received in react#35277. When a reply is
decoded on the server, a request-controlled reference id could resolve to an
arbitrary module export.
- resolveServerReference is the only place Server References are resolved
(client references go through resolveClientReference). On the server it now
requires the module and rejects any id whose resolved export was not
registered via registerServerReference. This bundler has no manifest to
allowlist against, so the registration tag is the equivalent check.
- requireModule reads only the module's own exports via hasOwnProperty,
preventing ids like "x#constructor" from reaching prototype-chain
properties, matching the other bundlers.
Test plan:
- yarn prettier and yarn eslint clean on the changed file
- yarn flow dom-node: No errors
ahacop added a commit to changebot-ai/widgets that referenced this pull request Aug 24, 2026
[cb skip]
Packages updated:
- react 18.3.1 -> 19.2.8 (dev)
- react-dom 18.3.1 -> 19.2.8 (dev)
- @types/react 18.3.26 -> 19.2.18 (dev)
- @types/react-dom 18.3.7 -> 19.2.4 (dev)
These are dev dependencies of @changebot/widgets-react, used to
compile the generated wrappers. The peer range stays >=16.8.0.
react-demo.html keeps loading React 18 from unpkg because React 19
publishes no UMD build, and that page uses the custom elements
directly rather than the wrapper.
== 19.2.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 (@unstubbable [#36566](https://github.com/facebook/react/pull/36566))
== 19.2.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.2.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.2.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.2.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.2.2 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.2.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.2.0 (October 1st, 2025)
Below is a list of all new features, APIs, and bug fixes.
Read the [React 19.2 release post](https://react.dev/blog/2025/10/01/react-19-2) for more information.
== New React Features
- [`<Activity>`](https://react.dev/reference/react/Activity): A new API to hide and restore the UI and internal state of its children.
- [`useEffectEvent`](https://react.dev/reference/react/useEffectEvent) is a React Hook that lets you extract non-reactive logic into an [Effect Event](https://react.dev/learn/separating-events-from-effects#declaring-an-effect-event).
- [`cacheSignal`](https://react.dev/reference/react/cacheSignal) (for RSCs) lets your know when the `cache()` lifetime is over.
- [React Performance tracks](https://react.dev/reference/dev-tools/react-performance-tracks) appear on the Performance panel’s timeline in your browser developer tools
== New React DOM Features
- Added resume APIs for partial pre-rendering with Web Streams:
- [`resume`](https://react.dev/reference/react-dom/server/resume): to resume a prerender to a stream.
- [`resumeAndPrerender`](https://react.dev/reference/react-dom/static/resumeAndPrerender): to resume a prerender to HTML.
- Added resume APIs for partial pre-rendering with Node Streams:
- [`resumeToPipeableStream`](https://react.dev/reference/react-dom/server/resumeToPipeableStream): to resume a prerender to a stream.
- [`resumeAndPrerenderToNodeStream`](https://react.dev/reference/react-dom/static/resumeAndPrerenderToNodeStream): to resume a prerender to HTML.
- Updated [`prerender`](https://react.dev/reference/react-dom/static/prerender) APIs to return a `postponed` state that can be passed to the `resume` APIs.
== Notable changes
- React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming `<ViewTransition>` Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
- Add Node Web Streams (`prerender`, `renderToReadableStream`) to server-side-rendering APIs for Node.js
- Use underscore instead of `:` IDs generated by useId
== All Changes
== React
- `<Activity />` was developed over many years, starting before `ClassComponent.setState` (@acdlite @sebmarkbage and many others)
- Stringify context as "SomeContext" instead of "SomeContext.Provider" (@kassens [#33507](https://github.com/facebook/react/pull/33507))
- Include stack of cause of React instrumentation errors with `%o` placeholder (@eps1lon [#34198](https://github.com/facebook/react/pull/34198))
- Fix infinite `useDeferredValue` loop in popstate event (@acdlite [#32821](https://github.com/facebook/react/pull/32821))
- Fix a bug when an initial value was passed to `useDeferredValue` (@acdlite [#34376](https://github.com/facebook/react/pull/34376))
- Fix a crash when submitting forms with Client Actions (@sebmarkbage [#33055](https://github.com/facebook/react/pull/33055))
- Hide/unhide the content of dehydrated suspense boundaries if they resuspend (@sebmarkbage [#32900](https://github.com/facebook/react/pull/32900))
- Avoid stack overflow on wide trees during Hot Reload (@sophiebits [#34145](https://github.com/facebook/react/pull/34145))
- Improve Owner and Component stacks in various places (@sebmarkbage, @eps1lon: [#33629](https://github.com/facebook/react/pull/33629), [#33724](https://github.com/facebook/react/pull/33724), [#32735](https://github.com/facebook/react/pull/32735), [#33723](https://github.com/facebook/react/pull/33723))
- Add `cacheSignal` (@sebmarkbage [#33557](https://github.com/facebook/react/pull/33557))
== React DOM
- Block on Suspensey Fonts during reveal of server-side-rendered content (@sebmarkbage [#33342](https://github.com/facebook/react/pull/33342))
- Use underscore instead of `:` for IDs generated by `useId` (@sebmarkbage, @eps1lon: [#32001](https://github.com/facebook/react/pull/32001), [https://github.com/facebook/react/pull/33342](https://github.com/facebook/react/pull/33342)[#33099](https://github.com/facebook/react/pull/33099), [#33422](https://github.com/facebook/react/pull/33422))
- Stop warning when ARIA 1.3 attributes are used (@Abdul-Omira [#34264](https://github.com/facebook/react/pull/34264))
- Allow `nonce` to be used on hoistable styles (@Andarist [#32461](https://github.com/facebook/react/pull/32461))
- Warn for using a React owned node as a Container if it also has text content (@sebmarkbage [#32774](https://github.com/facebook/react/pull/32774))
- s/HTML/text for for error messages if text hydration mismatches (@rickhanlonii [#32763](https://github.com/facebook/react/pull/32763))
- Fix a bug with `React.use` inside `React.lazy`\-ed Component (@hi-ogawa [#33941](https://github.com/facebook/react/pull/33941))
- Enable the `progressiveChunkSize` option for server-side-rendering APIs (@sebmarkbage [#33027](https://github.com/facebook/react/pull/33027))
- Fix a bug with deeply nested Suspense inside Suspense fallback when server-side-rendering (@gnoff [#33467](https://github.com/facebook/react/pull/33467))
- Avoid hanging when suspending after aborting while rendering (@gnoff [#34192](https://github.com/facebook/react/pull/34192))
- Add Node Web Streams to server-side-rendering APIs for Node.js (@sebmarkbage [#33475](https://github.com/facebook/react/pull/33475))
== React Server Components
- Preload `<img>` and `<link>` using hints before they're rendered (@sebmarkbage [#34604](https://github.com/facebook/react/pull/34604))
- Log error if production elements are rendered during development (@eps1lon [#34189](https://github.com/facebook/react/pull/34189))
- Fix a bug when returning a Temporary reference (e.g. a Client Reference) from Server Functions (@sebmarkbage [#34084](https://github.com/facebook/react/pull/34084), @denk0403 [#33761](https://github.com/facebook/react/pull/33761))
- Pass line/column to `filterStackFrame` (@eps1lon [#33707](https://github.com/facebook/react/pull/33707))
- Support Async Modules in Turbopack Server References (@lubieowoce [#34531](https://github.com/facebook/react/pull/34531))
- Add support for .mjs file extension in Webpack (@jennyscript [#33028](https://github.com/facebook/react/pull/33028))
- Fix a wrong missing key warning (@unstubbable [#34350](https://github.com/facebook/react/pull/34350))
- Make console log resolve in predictable order (@sebmarkbage [#33665](https://github.com/facebook/react/pull/33665))
== React Reconciler
- [createContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L255-L261) and [createHydrationContainer](https://github.com/facebook/react/blob/v19.2.0/packages/react-reconciler/src/ReactFiberReconciler.js#L305-L312) had their parameter order adjusted after `on*` handlers to account for upcoming experimental APIs
== 19.1.8 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.1.7 (@unstubbable [#36567](https://github.com/facebook/react/pull/36567))
== 19.1.7 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.1.6 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.1.5 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.1.4 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.1.3 (Dec 11, 2025)
== React Server Components
- Move `react-server-dom-webpack/*.unbundled` to private `react-server-dom-unbundled` (@eps1lon [#35290](https://github.com/facebook/react/pull/35290))
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.1.2 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.1.1 (July 28, 2025)
== React
* Fixed Owner Stacks to work with ES2015 function.name semantics ([#33680](https://github.com/facebook/react/pull/33680) by @hoxyq)
== 19.1.0 (March 28, 2025)
== Owner Stack
An Owner Stack is a string representing the components that are directly responsible for rendering a particular component. You can log Owner Stacks when debugging or use Owner Stacks to enhance error overlays or other development tools. Owner Stacks are only available in development builds. Component Stacks in production are unchanged.
* An Owner Stack is a development-only stack trace that helps identify which components are responsible for rendering a particular component. An Owner Stack is distinct from a Component Stacks, which shows the hierarchy of components leading to an error.
* The [captureOwnerStack API](https://react.dev/reference/react/captureOwnerStack) is only available in development mode and returns a Owner Stack, if available. The API can be used to enhance error overlays or log component relationships when debugging. [#29923](https://github.com/facebook/react/pull/29923), [#32353](https://github.com/facebook/react/pull/32353), [#30306](https://github.com/facebook/react/pull/30306),
[#32538](https://github.com/facebook/react/pull/32538), [#32529](https://github.com/facebook/react/pull/32529), [#32538](https://github.com/facebook/react/pull/32538)
== React
* Enhanced support for Suspense boundaries to be used anywhere, including the client, server, and during hydration. [#32069](https://github.com/facebook/react/pull/32069), [#32163](https://github.com/facebook/react/pull/32163), [#32224](https://github.com/facebook/react/pull/32224), [#32252](https://github.com/facebook/react/pull/32252)
* Reduced unnecessary client rendering through improved hydration scheduling [#31751](https://github.com/facebook/react/pull/31751)
* Increased priority of client rendered Suspense boundaries [#31776](https://github.com/facebook/react/pull/31776)
* Fixed frozen fallback states by rendering unfinished Suspense boundaries on the client. [#31620](https://github.com/facebook/react/pull/31620)
* Reduced garbage collection pressure by improving Suspense boundary retries. [#31667](https://github.com/facebook/react/pull/31667)
* Fixed erroneous “Waiting for Paint” log when the passive effect phase was not delayed [#31526](https://github.com/facebook/react/pull/31526)
* Fixed a regression causing key warnings for flattened positional children in development mode. [#32117](https://github.com/facebook/react/pull/32117)
* Updated `useId` to use valid CSS selectors, changing format from `:r123:` to `«r123»`. [#32001](https://github.com/facebook/react/pull/32001)
* Added a dev-only warning for null/undefined created in useEffect, useInsertionEffect, and useLayoutEffect. [#32355](https://github.com/facebook/react/pull/32355)
* Fixed a bug where dev-only methods were exported in production builds. React.act is no longer available in production builds. [#32200](https://github.com/facebook/react/pull/32200)
* Improved consistency across prod and dev to improve compatibility with Google Closure Compiler and bindings [#31808](https://github.com/facebook/react/pull/31808)
* Improve passive effect scheduling for consistent task yielding. [#31785](https://github.com/facebook/react/pull/31785)
* Fixed asserts in React Native when passChildrenWhenCloningPersistedNodes is enabled for OffscreenComponent rendering. [#32528](https://github.com/facebook/react/pull/32528)
* Fixed component name resolution for Portal [#32640](https://github.com/facebook/react/pull/32640)
* Added support for beforetoggle and toggle events on the dialog element. [#32479](https://github.com/facebook/react/pull/32479)
== React DOM
* Fixed double warning when the `href` attribute is an empty string [#31783](https://github.com/facebook/react/pull/31783)
* Fixed an edge case where `getHoistableRoot()` didn’t work properly when the container was a Document [#32321](https://github.com/facebook/react/pull/32321)
* Removed support for using HTML comments (e.g. `<!-- -->`) as a DOM container. [#32250](https://github.com/facebook/react/pull/32250)
* Added support for `<script>` and `<template>` tags to be nested within `<select>` tags. [#31837](https://github.com/facebook/react/pull/31837)
* Fixed responsive images to be preloaded as HTML instead of headers [#32445](https://github.com/facebook/react/pull/32445)
== use-sync-external-store
* Added `exports` field to `package.json` for `use-sync-external-store` to support various entrypoints. [#25231](https://github.com/facebook/react/pull/25231)
== React Server Components
* Added `unstable_prerender`, a new experimental API for prerendering React Server Components on the server [#31724](https://github.com/facebook/react/pull/31724)
* Fixed an issue where streams would hang when receiving new chunks after a global error [#31840](https://github.com/facebook/react/pull/31840), [#31851](https://github.com/facebook/react/pull/31851)
* Fixed an issue where pending chunks were counted twice. [#31833](https://github.com/facebook/react/pull/31833)
* Added support for streaming in edge environments [#31852](https://github.com/facebook/react/pull/31852)
* Added support for sending custom error names from a server so that they are available in the client for console replaying. [#32116](https://github.com/facebook/react/pull/32116)
* Updated the server component wire format to remove IDs for hints and console.log because they have no return value [#31671](https://github.com/facebook/react/pull/31671)
* Exposed `registerServerReference` in client builds to handle server references in different environments. [#32534](https://github.com/facebook/react/pull/32534)
* Added react-server-dom-parcel package which integrates Server Components with the [Parcel bundler](https://parceljs.org/) [#31725](https://github.com/facebook/react/pull/31725), [#32132](https://github.com/facebook/react/pull/32132), [#31799](https://github.com/facebook/react/pull/31799), [#32294](https://github.com/facebook/react/pull/32294), [#31741](https://github.com/facebook/react/pull/31741)
== 19.0.7 (June 1, 2026)
== React Server Components
- Fixed missing `FormData` entries in Server Actions which regressed in 19.0.6 (@unstubbable [#36568](https://github.com/facebook/react/pull/36568))
== 19.0.6 (May 6, 2026)
== React Server Components
- Type hardening and performance improvements (@eps1lon, @unstubbable [#36425](https://github.com/facebook/react/pull/36425))
== 19.0.5 (March 18, 2026)
== React Server Components
- Add more cycle protections (@eps1lon, @unstubbable [#36236](https://github.com/facebook/react/pull/36236))
== 19.0.4 (Jan 26, 2026)
== React Server Components
- Add more DoS mitigations to Server Actions, and harden Server Components (@gnoff, @lubieowoce, @sebmarkbage, @unstubbable [#35632](https://github.com/facebook/react/pull/35632))
== 19.0.3 (Dec 11, 2025)
== React Server Components
- Add extra loop protection to React Server Functions (@sebmarkbage [#35351](https://github.com/facebook/react/pull/35351))
== 19.0.2 (Dec 11, 2025)
== React Server Components
- Patch Promise cycles and toString on Server Functions (@sebmarkbage, @unstubbable [#35289](https://github.com/facebook/react/pull/35289), [#35345](https://github.com/facebook/react/pull/35345))
== 19.0.1 (Dec 3, 2025)
== React Server Components
- Bring React Server Component fixes to Server Actions (@sebmarkbage [#35277](https://github.com/facebook/react/pull/35277))
== 19.0.0 (December 5, 2024)
Below is a list of all new features, APIs, deprecations, and breaking changes. Read [React 19 release post](https://react.dev/blog/2024/04/25/react-19) and [React 19 upgrade guide](https://react.dev/blog/2024/04/25/react-19-upgrade-guide) for more information.
> Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.
== New Features
== React
* Actions: `startTransition` can now accept async functions. Functions passed to `startTransition` are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like `fetch()` in the pending state, and provides support for error handling, and optimistic updates. * `useActionState`: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form `action` prop to support progressive enhancement in forms. * `useOptimistic`: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value. * `use`: is a new API that allows reading resources in render. In React 19, `use` accepts a promise or Context. If provided a promise, `use` will suspend until a value is resolved. `use` can only be used in render but can be called conditionally. * `ref` as a prop: Refs can now be used as props, removing the need for `forwardRef`. * **Suspense sibling pre-warming**: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
== React DOM Client
* `<form> action` prop: Form Actions allow you to manage forms automatically and integrate with `useFormStatus`. When a `<form> action` succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new `requestFormReset` API. * `<button> and <input> formAction` prop: Actions can be passed to the `formAction` prop to configure form submission behavior. This allows using different Actions depending on the input. * `useFormStatus`: is a new hook that provides the status of the parent `<form> action`, as if the form was a Context provider. The hook returns the values: `pending`, `data`, `method`, and `action`. * Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the `<head>` section of the document. * Support for Stylesheets: React 19 will ensure stylesheets are inserted into the `<head>` on the client before revealing the content of a Suspense boundary that depends on that stylesheet. * Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication. * Support for preloading resources: React 19 ships with `preinit`, `preload`, `prefetchDNS`, and `preconnect` APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
== React DOM Server
* Added `prerender` and `prerenderToNodeStream` APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike `renderToString`, they wait for data to load for HTML generation.
== React Server Components
* RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See [docs](https://19.react.dev/reference/rsc/server-components) for how to support React Server Components.
== Deprecations
* Deprecated: `element.ref` access: React 19 supports ref as a prop, so we’re deprecating `element.ref` in favor of `element.props.ref`. Accessing will result in a warning. * `react-test-renderer`: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro)
== Breaking Changes
React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to `18.3.1`, where we've added additional deprecation warnings. Check out the [upgrade guide](https://19.react.dev/blog/2024/04/25/react-19-upgrade-guide) for more details and guidance on codemodding.
== React
* New JSX Transform is now required: We introduced [a new JSX transform](https://legacy.reactjs.org/blog/2020/09/22/introducing-the-new-jsx-transform.html) in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform. * Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced `onUncaughtError` and `onCaughtError` methods to `createRoot` and `hydrateRoot` to customize this error handling. * Removed: `propTypes`: Using `propTypes` will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution. * Removed: `defaultProps` for functions: ES6 default parameters can be used in place. Class components continue to support `defaultProps` since there is no ES6 alternative. * Removed: `contextTypes` and `getChildContext`: Legacy Context for class components has been removed in favor of the `contextType` API. * Removed: string refs: Any usage of string refs need to be migrated to ref callbacks. * Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions. * Removed: `React.createFactory`: Now that JSX is broadly supported, all `createFactory` usage can be migrated to JSX components. * Removed: `react-test-renderer/shallow`: This has been a re-export of [react-shallow-renderer](https://github.com/enzymejs/react-shallow-renderer) since React 18\. If needed, you can continue to use the third-party package directly. We recommend using [@testing-library/react](https://testing-library.com/docs/react-testing-library/intro/) or [@testing-library/react-native](https://testing-library.com/docs/react-native-testing-library/intro) instead.
== React DOM
* Removed: `react-dom/test-utils`: We’ve moved `act` from `react-dom/test-utils` to react. All other utilities have been removed. * Removed: `ReactDOM`.`render`, `ReactDOM`.`hydrate`: These have been removed in favor of the concurrent equivalents: `ReactDOM`.`createRoot` and `ReactDOM.hydrateRoot`. * Removed: `unmountComponentAtNode`: Removed in favor of `root.unmount()`. * Removed: `ReactDOM`.`findDOMNode`: You can replace `ReactDOM`.`findDOMNode` with DOM Refs.
== Notable Changes
== React
* `<Context>` as a provider: You can now render `<Context>` as a provider instead of `<Context.Provider>`. * Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback. * `useDeferredValue` initial value argument: When provided, `useDeferredValue` will return the initial value for the initial render of a component, then schedule a re-render in the background with the `deferredValue` returned. * Support for Custom Elements: React 19 now passes all tests on [Custom Elements Everywhere](https://custom-elements-everywhere.com/). * StrictMode changes: `useMemo` and `useCallback` will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount. * UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as [esm.sh](http://esm.sh).
== React DOM
* Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content. * Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS. == TypeScript Changes
The most common changes can be codemodded with `npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files`.
* Removed deprecated TypeScript types: * `ReactChild` (replacement: `React.ReactElement | number | string)` * `ReactFragment` (replacement: `Iterable<React.ReactNode>`) * `ReactNodeArray` (replacement: `ReadonlyArray<React.ReactNode>`) * `ReactText` (replacement: `number | string`) * `VoidFunctionComponent` (replacement: `FunctionComponent`) * `VFC` (replacement: `FC`) * Moved to `prop-types`: `Requireable`, `ValidationMap`, `Validator`, `WeakValidationMap` * Moved to `create-react-class`: `ClassicComponentClass`, `ClassicComponent`, `ClassicElement`, `ComponentSpec`, `Mixin`, `ReactChildren`, `ReactHTML`, `ReactSVG`, `SFCFactory` * Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error. * Require initial argument to `useRef`: The initial argument is now required to match `useState`, `createContext` etc * Refs are mutable by default: Ref objects returned from `useRef()` are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to. * Strict `ReactElement` typing: The props of React elements now default to `unknown` instead of `any` if the element is typed as `ReactElement` * JSX namespace in TypeScript: The global `JSX` namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: `import { JSX } from 'react'` * Better `useReducer` typings: Most `useReducer` usage should not require explicit type arguments. For example, ```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer(reducer)
```
or
```diff
-useReducer<React.Reducer<State, Action>>(reducer)
+useReducer<State, Action>(reducer)
```
== All Changes
== React
* Add support for async Actions ([\#26621](https://github.com/facebook/react/pull/26621), [\#26726](https://github.com/facebook/react/pull/26726), [\#28078](https://github.com/facebook/react/pull/28078), [\#28097](https://github.com/facebook/react/pull/28097), [\#29226](https://github.com/facebook/react/pull/29226), [\#29618](https://github.com/facebook/react/pull/29618), [\#29670](https://github.com/facebook/react/pull/29670), [\#26716](https://github.com/facebook/react/pull/26716) by [@acdlite](https://github.com/acdlite) and [@sebmarkbage](https://github.com/sebmarkbage)) * Add `useActionState()` hook to update state based on the result of a Form Action ([\#27270](https://github.com/facebook/react/pull/27270), [\#27278](https://github.com/facebook/react/pull/27278), [\#27309](https://github.com/facebook/react/pull/27309), [\#27302](https://github.com/facebook/react/pull/27302), [\#27307](https://github.com/facebook/react/pull/27307), [\#27366](https://github.com/facebook/react/pull/27366), [\#27370](https://github.com/facebook/react/pull/27370), [\#27321](https://github.com/facebook/react/pull/27321), [\#27374](https://github.com/facebook/react/pull/27374), [\#27372](https://github.com/facebook/react/pull/27372), [\#27397](https://github.com/facebook/react/pull/27397), [\#27399](https://github.com/facebook/react/pull/27399), [\#27460](https://github.com/facebook/react/pull/27460), [\#28557](https://github.com/facebook/react/pull/28557), [\#27570](https://github.com/facebook/react/pull/27570), [\#27571](https://github.com/facebook/react/pull/27571), [\#28631](https://github.com/facebook/react/pull/28631), [\#28788](https://github.com/facebook/react/pull/28788), [\#29694](https://github.com/facebook/react/pull/29694), [\#29695](https://github.com/facebook/react/pull/29695), [\#29694](https://github.com/facebook/react/pull/29694), [\#29665](https://github.com/facebook/react/pull/29665), [\#28232](https://github.com/facebook/react/pull/28232), [\#28319](https://github.com/facebook/react/pull/28319) by [@acdlite](https://github.com/acdlite), [@eps1lon](https://github.com/eps1lon), and [@rickhanlonii](https://github.com/rickhanlonii)) * Add `use()` API to read resources in render ([\#25084](https://github.com/facebook/react/pull/25084), [\#25202](https://github.com/facebook/react/pull/25202), [\#25207](https://github.com/facebook/react/pull/25207), [\#25214](https://github.com/facebook/react/pull/25214), [\#25226](https://github.com/facebook/react/pull/25226), [\#25247](https://github.com/facebook/react/pull/25247), [\#25539](https://github.com/facebook/react/pull/25539), [\#25538](https://github.com/facebook/react/pull/25538), [\#25537](https://github.com/facebook/react/pull/25537), [\#25543](https://github.com/facebook/react/pull/25543), [\#25561](https://github.com/facebook/react/pull/25561), [\#25620](https://github.com/facebook/react/pull/25620), [\#25615](https://github.com/facebook/react/pull/25615), [\#25922](https://github.com/facebook/react/pull/25922), [\#25641](https://github.com/facebook/react/pull/25641), [\#25634](https://github.com/facebook/react/pull/25634), [\#26232](https://github.com/facebook/react/pull/26232), [\#26536](https://github.com/facebook/react/pull/26535), [\#26739](https://github.com/facebook/react/pull/26739), [\#28233](https://github.com/facebook/react/pull/28233) by [@acdlite](https://github.com/acdlite), [@MofeiZ](https://github.com/mofeiZ), [@sebmarkbage](https://github.com/sebmarkbage), [@sophiebits](https://github.com/sophiebits), [@eps1lon](https://github.com/eps1lon), and [@hansottowirtz](https://github.com/hansottowirtz)) * Add `useOptimistic()` hook to display mutated state optimistically during an async mutation ([\#26740](https://github.com/facebook/react/pull/26740), [\#26772](https://github.com/facebook/react/pull/26772), [\#27277](https://github.com/facebook/react/pull/27277), [\#27453](https://github.com/facebook/react/pull/27453), [\#27454](https://github.com/facebook/react/pull/27454), [\#27936](https://github.com/facebook/react/pull/27936) by [@acdlite](https://github.com/acdlite)) * Added an `initialValue` argument to `useDeferredValue()` hook ([\#27500](https://github.com/facebook/react/pull/27500), [\#27509](https://github.com/facebook/react/pull/27509), [\#27512](https://github.com/facebook/react/pull/27512), [\#27888](https://github.com/facebook/react/pull/27888), [\#27550](https://github.com/facebook/react/pull/27550) by [@acdlite](https://github.com/acdlite)) * Support refs as props, warn on `element.ref` access ([\#28348](https://github.com/facebook/react/pull/28348), [\#28464](https://github.com/facebook/react/pull/28464), [\#28731](https://github.com/facebook/react/pull/28731) by [@acdlite](https://github.com/acdlite)) * Support Custom Elements ([\#22184](https://github.com/facebook/react/pull/22184), [\#26524](https://github.com/facebook/react/pull/26524), [\#26523](https://github.com/facebook/react/pull/26523), [\#27511](https://github.com/facebook/react/pull/27511), [\#24541](https://github.com/facebook/react/pull/24541) by [@josepharhar](https://github.com/josepharhar), [@sebmarkbage](https://github.com/sebmarkbage), [@gnoff](https://github.com/gnoff) and [@eps1lon](https://github.com/eps1lon)) * Add ref cleanup function ([\#25686](https://github.com/facebook/react/pull/25686), [\#28883](https://github.com/facebook/react/pull/28883), [\#28910](https://github.com/facebook/react/pull/28910) by [@sammy-SC](https://github.com/sammy-SC), [@jackpope](https://github.com/jackpope), and [@kassens](https://github.com/kassens)) * Sibling pre-rendering replaced by sibling pre-warming ([\#26380](https://github.com/facebook/react/pull/26380), [\#26549](https://github.com/facebook/react/pull/26549), [\#30761](https://github.com/facebook/react/pull/30761), [\#30800](https://github.com/facebook/react/pull/30800), [\#30762](https://github.com/facebook/react/pull/30762), [\#30879](https://github.com/facebook/react/pull/30879), [\#30934](https://github.com/facebook/react/pull/30934), [\#30952](https://github.com/facebook/react/pull/30952), [\#31056](https://github.com/facebook/react/pull/31056), [\#31452](https://github.com/facebook/react/pull/31452) by [@sammy-SC](https://github.com/sammy-SC), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@jackpope](https://github.com/jackpope), [@rickhanlonii](https://github.com/rickhanlonii)) * Don’t rethrow errors at the root ([\#28627](https://github.com/facebook/react/pull/28627), [\#28641](https://github.com/facebook/react/pull/28641) by [@sebmarkbage](https://github.com/sebmarkbage)) * Batch sync discrete, continuous, and default lanes ([\#25700](https://github.com/facebook/react/pull/25700) by [@tyao1](https://github.com/tyao1)) * Switch `<Context>` to mean `<Context.Provider>` ([\#28226](https://github.com/facebook/react/pull/28226) by [@gaearon](https://github.com/gaearon)) * Changes to *StrictMode* * Handle `info`, `group`, and `groupCollapsed` in *StrictMode* logging ([\#25172](https://github.com/facebook/react/pull/25172) by [@timneutkens](https://github.com/timneutkens)) * Refs are now attached/detached/attached in *StrictMode* ([\#25049](https://github.com/facebook/react/pull/25049) by [@sammy-SC](https://github.com/sammy-SC)) * Fix `useSyncExternalStore()` hydration in *StrictMode* ([\#26791](https://github.com/facebook/react/pull/26791) by [@sophiebits](https://github.com/sophiebits)) * Always trigger `componentWillUnmount()` in *StrictMode* ([\#26842](https://github.com/facebook/react/pull/26842) by [@tyao1](https://github.com/tyao1)) * Restore double invoking `useState()` and `useReducer()` initializer functions in *StrictMode* ([\#28248](https://github.com/facebook/react/pull/28248) by [@eps1lon](https://github.com/eps1lon)) * Reuse memoized result from first pass ([\#25583](https://github.com/facebook/react/pull/25583) by [@acdlite](https://github.com/acdlite)) * Fix `useId()` in *StrictMode* ([\#25713](https://github.com/facebook/react/pull/25713) by [@gnoff](https://github.com/gnoff)) * Add component name to *StrictMode* error messages ([\#25718](https://github.com/facebook/react/pull/25718) by [@sammy-SC](https://github.com/sammy-SC)) * Add support for rendering BigInt ([\#24580](https://github.com/facebook/react/pull/24580) by [@eps1lon](https://github.com/eps1lon)) * `act()` no longer checks `shouldYield` which can be inaccurate in test environments ([\#26317](https://github.com/facebook/react/pull/26317) by [@acdlite](https://github.com/acdlite)) * Warn when keys are spread with props ([\#25697](https://github.com/facebook/react/pull/25697), [\#26080](https://github.com/facebook/react/pull/26080) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Generate sourcemaps for production build artifacts ([\#26446](https://github.com/facebook/react/pull/26446) by [@markerikson](https://github.com/markerikson)) * Improve stack diffing algorithm ([\#27132](https://github.com/facebook/react/pull/27132) by [@KarimP](https://github.com/KarimP)) * Suspense throttling lowered from 500ms to 300ms ([\#26803](https://github.com/facebook/react/pull/26803) by [@acdlite](https://github.com/acdlite)) * Lazily propagate context changes ([\#20890](https://github.com/facebook/react/pull/20890) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Immediately rerender pinged fiber ([\#25074](https://github.com/facebook/react/pull/25074) by [@acdlite](https://github.com/acdlite)) * Move update scheduling to microtask ([\#26512](https://github.com/facebook/react/pull/26512) by [@acdlite](https://github.com/acdlite)) * Consistently apply throttled retries ([\#26611](https://github.com/facebook/react/pull/26611), [\#26802](https://github.com/facebook/react/pull/26802) by [@acdlite](https://github.com/acdlite)) * Suspend Thenable/Lazy if it's used in React.Children ([\#28284](https://github.com/facebook/react/pull/28284) by [@sebmarkbage](https://github.com/sebmarkbage)) * Detect infinite update loops caused by render phase updates ([\#26625](https://github.com/facebook/react/pull/26625) by [@acdlite](https://github.com/acdlite)) * Update conditional hooks warning ([\#29626](https://github.com/facebook/react/pull/29626) by [@sophiebits](https://github.com/sophiebits)) * Update error URLs to go to new docs ([\#27240](https://github.com/facebook/react/pull/27240) by [@rickhanlonii](https://github.com/rickhanlonii)) * Rename the `react.element` symbol to `react.transitional.element` ([\#28813](https://github.com/facebook/react/pull/28813) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix crash when suspending in shell during `useSyncExternalStore()` re-render ([\#27199](https://github.com/facebook/react/pull/27199) by [@acdlite](https://github.com/acdlite)) * Fix incorrect “detected multiple renderers" error in tests ([\#22797](https://github.com/facebook/react/pull/22797) by [@eps1lon](https://github.com/eps1lon)) * Fix bug where effect cleanup may be called twice after bailout ([\#26561](https://github.com/facebook/react/pull/26561) by [@acdlite](https://github.com/acdlite)) * Fix suspending in shell during discrete update ([\#25495](https://github.com/facebook/react/pull/25495) by [@acdlite](https://github.com/acdlite)) * Fix memory leak after repeated setState bailouts ([\#25309](https://github.com/facebook/react/pull/25309) by [@acdlite](https://github.com/acdlite)) * Fix `useSyncExternalStore()` dropped update when state is dispatched in render phase ([\#25578](https://github.com/facebook/react/pull/25578) by [@pandaiolo](https://github.com/pandaiolo)) * Fix logging when rendering a lazy fragment ([\#30372](https://github.com/facebook/react/pull/30372) by [@tom-sherman](https://github.com/tom-sherman)) * Remove string refs ([\#25383](https://github.com/facebook/react/pull/25383), [\#28322](https://github.com/facebook/react/pull/28322) by [@eps1lon](https://github.com/eps1lon) and [@acdlite](https://github.com/acdlite)) * Remove Legacy Context (\#30319 by [@kassens](https://github.com/kassens)) * Remove `RefreshRuntime.findAffectedHostInstances` ([\#30538](https://github.com/facebook/react/pull/30538) by [@gaearon](https://github.com/gaearon)) * Remove client caching from `cache()` API ([\#27977](https://github.com/facebook/react/pull/27977), [\#28250](https://github.com/facebook/react/pull/28250) by [@acdlite](https://github.com/acdlite) and [@gnoff](https://github.com/gnoff)) * Remove `propTypes` ([\#28324](https://github.com/facebook/react/pull/28324), [\#28326](https://github.com/facebook/react/pull/28326) by [@gaearon](https://github.com/gaearon)) * Remove `defaultProps` support, except for classes ([\#28733](https://github.com/facebook/react/pull/28733) by [@acdlite](https://github.com/acdlite)) * Remove UMD builds ([\#28735](https://github.com/facebook/react/pull/28735) by [@gnoff](https://github.com/gnoff)) * Remove delay for non-transition updates ([\#26597](https://github.com/facebook/react/pull/26597) by [@acdlite](https://github.com/acdlite)) * Remove `createFactory` ([\#27798](https://github.com/facebook/react/pull/27798) by [@kassens](https://github.com/kassens))
== React DOM
* Adds Form Actions to handle form submission ([\#26379](https://github.com/facebook/react/pull/26379), [\#26674](https://github.com/facebook/react/pull/26674), [\#26689](https://github.com/facebook/react/pull/26689), [\#26708](https://github.com/facebook/react/pull/26708), [\#26714](https://github.com/facebook/react/pull/26714), [\#26735](https://github.com/facebook/react/pull/26735), [\#26846](https://github.com/facebook/react/pull/26846), [\#27358](https://github.com/facebook/react/pull/27358), [\#28056](https://github.com/facebook/react/pull/28056) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), and [@jupapios](https://github.com/jupapios)) * Add `useFormStatus()` hook to provide status information of the last form submission ([\#26719](https://github.com/facebook/react/pull/26719), [\#26722](https://github.com/facebook/react/pull/26722), [\#26788](https://github.com/facebook/react/pull/26788), [\#29019](https://github.com/facebook/react/pull/29019), [\#28728](https://github.com/facebook/react/pull/28728), [\#28413](https://github.com/facebook/react/pull/28413) by [@acdlite](https://github.com/acdlite) and [@eps1lon](https://github.com/eps1lon)) * Support for Document Metadata. Adds `preinit`, `preinitModule`, `preconnect`, `prefetchDNS`, `preload`, and `preloadModule` APIs. * [\#25060](https://github.com/facebook/react/pull/25060), [\#25243](https://github.com/facebook/react/pull/25243), [\#25388](https://github.com/facebook/react/pull/25388), [\#25432](https://github.com/facebook/react/pull/25432), [\#25436](https://github.com/facebook/react/pull/25436), [\#25426](https://github.com/facebook/react/pull/25426), [\#25500](https://github.com/facebook/react/pull/25500), [\#25480](https://github.com/facebook/react/pull/25480), [\#25508](https://github.com/facebook/react/pull/25508), [\#25515](https://github.com/facebook/react/pull/25515), [\#25514](https://github.com/facebook/react/pull/25514), [\#25532](https://github.com/facebook/react/pull/25532), [\#25536](https://github.com/facebook/react/pull/25536), [\#25534](https://github.com/facebook/react/pull/25534), [\#25546](https://github.com/facebook/react/pull/25546), [\#25559](https://github.com/facebook/react/pull/25559), [\#25569](https://github.com/facebook/react/pull/25569), [\#25599](https://github.com/facebook/react/pull/25599), [\#25689](https://github.com/facebook/react/pull/25689), [\#26106](https://github.com/facebook/react/pull/26106), [\#26152](https://github.com/facebook/react/pull/26152), [\#26239](https://github.com/facebook/react/pull/26239), [\#26237](https://github.com/facebook/react/pull/26237), [\#26280](https://github.com/facebook/react/pull/26280), [\#26154](https://github.com/facebook/react/pull/26154), [\#26256](https://github.com/facebook/react/pull/26256), [\#26353](https://github.com/facebook/react/pull/26353), [\#26427](https://github.com/facebook/react/pull/26427), [\#26450](https://github.com/facebook/react/pull/26450), [\#26502](https://github.com/facebook/react/pull/26502), [\#26514](https://github.com/facebook/react/pull/26514), [\#26531](https://github.com/facebook/react/pull/26531), [\#26532](https://github.com/facebook/react/pull/26532), [\#26557](https://github.com/facebook/react/pull/26557), [\#26871](https://github.com/facebook/react/pull/26871), [\#26881](https://github.com/facebook/react/pull/26881), [\#26877](https://github.com/facebook/react/pull/26877), [\#26873](https://github.com/facebook/react/pull/26873), [\#26880](https://github.com/facebook/react/pull/26880), [\#26942](https://github.com/facebook/react/pull/26942), [\#26938](https://github.com/facebook/react/pull/26938), [\#26940](https://github.com/facebook/react/pull/26940), [\#26939](https://github.com/facebook/react/pull/26939), [\#27030](https://github.com/facebook/react/pull/27030), [\#27201](https://github.com/facebook/react/pull/27201), [\#27212](https://github.com/facebook/react/pull/27212), [\#27217](https://github.com/facebook/react/pull/27217), [\#27218](https://github.com/facebook/react/pull/27218), [\#27220](https://github.com/facebook/react/pull/27220), [\#27224](https://github.com/facebook/react/pull/27224), [\#27223](https://github.com/facebook/react/pull/27223), [\#27269](https://github.com/facebook/react/pull/27269), [\#27260](https://github.com/facebook/react/pull/27260), [\#27347](https://github.com/facebook/react/pull/27347), [\#27346](https://github.com/facebook/react/pull/27346), [\#27361](https://github.com/facebook/react/pull/27361), [\#27400](https://github.com/facebook/react/pull/27400), [\#27541](https://github.com/facebook/react/pull/27541), [\#27610](https://github.com/facebook/react/pull/27610), [\#28110](https://github.com/facebook/react/pull/28110), [\#29693](https://github.com/facebook/react/pull/29693), [\#29732](https://github.com/facebook/react/pull/29732), [\#29811](https://github.com/facebook/react/pull/29811), [\#27586](https://github.com/facebook/react/pull/27586), [\#28069](https://github.com/facebook/react/pull/28069) by [@gnoff](https://github.com/gnoff), [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@kassens](https://github.com/kassens), [@sokra](https://github.com/sokra), [@sweetliquid](https://github.com/sweetliquid) * Add `fetchPriority` to `<img>` and `<link>` ([\#25927](https://github.com/facebook/react/pull/25927) by [@styfle](https://github.com/styfle)) * Add support for SVG `transformOrigin` prop ([\#26130](https://github.com/facebook/react/pull/26130) by [@arav-ind](https://github.com/arav-ind)) * Add support for `onScrollEnd` event ([\#26789](https://github.com/facebook/react/pull/26789) by [@devongovett](https://github.com/devongovett)) * Allow `<hr>` as child of `<select>` ([\#27632](https://github.com/facebook/react/pull/27632) by [@SouSingh](https://github.com/SouSingh)) * Add support for Popover API ([\#27981](https://github.com/facebook/react/pull/27981) by [@eps1lon](https://github.com/eps1lon)) * Add support for `inert` ([\#24730](https://github.com/facebook/react/pull/24730) by [@eps1lon](https://github.com/eps1lon)) * Add support for `imageSizes` and `imageSrcSet` ([\#22550](https://github.com/facebook/react/pull/22550) by [@eps1lon](https://github.com/eps1lon)) * Synchronously flush transitions in popstate events ([\#26025](https://github.com/facebook/react/pull/26025), [\#27559](https://github.com/facebook/react/pull/27559), [\#27505](https://github.com/facebook/react/pull/27505), [\#30759](https://github.com/facebook/react/pull/30759) by [@tyao1](https://github.com/tyao1) and [@acdlite](https://github.com/acdlite)) * `flushSync` exhausts queue even if something throws ([\#26366](https://github.com/facebook/react/pull/26366) by [@acdlite](https://github.com/acdlite)) * Throw error if `react` and `react-dom` versions don’t match ([\#29236](https://github.com/facebook/react/pull/29236) by [@acdlite](https://github.com/acdlite)) * Ensure `srcset` and `src` are assigned last on `<img>` instances ([\#30340](https://github.com/facebook/react/pull/30340) by [@gnoff](https://github.com/gnoff)) * Javascript URLs are replaced with functions that throw errors ([\#26507](https://github.com/facebook/react/pull/26507), [\#29808](https://github.com/facebook/react/pull/29808) by [@sebmarkbage](https://github.com/sebmarkbage) and [@kassens](https://github.com/kassens)) * Treat toggle and beforetoggle as discrete events ([\#29176](https://github.com/facebook/react/pull/29176) by [@eps1lon](https://github.com/eps1lon)) * Filter out empty `src` and `href` attributes (unless for `<a href=”” />`) ([\#18513](https://github.com/facebook/react/pull/18513), [\#28124](https://github.com/facebook/react/pull/28124) by [@bvaughn](https://github.com/bvaughn) and [@eps1lon](https://github.com/eps1lon)) * Fix unitless `scale` style property ([\#25601](https://github.com/facebook/react/pull/25601) by [@JonnyBurger](https://github.com/JonnyBurger)) * Fix `onChange` error message for controlled `<select>` ([\#27740](https://github.com/facebook/react/pull/27740) by [@Biki-das](https://github.com/Biki-das)) * Fix focus restore in child windows after element reorder ([\#30951](https://github.com/facebook/react/pull/30951) by [@ling1726](https://github.com/ling1726)) * Remove `render`, `hydrate`, `findDOMNode`, `unmountComponentAtNode`, `unstable_createEventHandle`, `unstable_renderSubtreeIntoContainer`, and `unstable_runWithPriority`. Move `createRoot` and `hydrateRoot` to `react-dom/client`. ([\#28271](https://github.com/facebook/react/pull/28271) by [@gnoff](https://github.com/gnoff)) * Remove `test-utils` ([\#28541](https://github.com/facebook/react/pull/28541) by [@eps1lon](https://github.com/eps1lon)) * Remove `unstable_flushControlled` ([\#26397](https://github.com/facebook/react/pull/26397) by [@kassens](https://github.com/kassens)) * Remove legacy mode ([\#28468](https://github.com/facebook/react/pull/28468) by [@gnoff](https://github.com/gnoff)) * Remove `renderToStaticNodeStream()` ([\#28873](https://github.com/facebook/react/pull/28873) by @gnoff) * Remove `unstable_renderSubtreeIntoContainer` ([\#29771](https://github.com/facebook/react/pull/29771) by [@kassens](https://github.com/kassens))
== React DOM Server
* Stable release of React Server Components ([Many, many PRs](https://github.com/facebook/react/pulls?q=is%3Apr+is%3Aclosed+%5BFlight%5D+in%3Atitle+created%3A%3C2024-12-01+) by [@sebmarkbage](https://github.com/sebmarkbage), [@acdlite](https://github.com/acdlite), [@gnoff](https://github.com/gnoff), [@sammy-SC](https://github.com/sammy-SC), [@gaearon](https://github.com/gaearon), [@sophiebits](https://github.com/sophiebits), [@unstubbable](https://github.com/unstubbable), [@lubieowoce](https://github.com/lubieowoce))
* Support Server Actions ([\#26124](https://github.com/facebook/react/pull/26124), [\#26632](https://github.com/facebook/react/pull/26632), [\#27459](https://github.com/facebook/react/pull/27459) by [@sebmarkbage](https://github.com/sebmarkbage) and [@acdlite](https://github.com/acdlite)) * Changes to SSR * Add external runtime which bootstraps hydration on the client for binary transparency ([\#25437](https://github.com/facebook/react/pull/25437), [\#26169](https://github.com/facebook/react/pull/26169), [\#25499](https://github.com/facebook/react/pull/25499) by [@MofeiZ](https://github.com/mofeiZ) and [@acdlite](https://github.com/acdlite)) * Support subresource integrity for `bootstrapScripts` and `bootstrapModules` ([\#25104](https://github.com/facebook/react/pull/25104) by [@gnoff](https://github.com/gnoff)) * Fix null bytes written at text chunk boundaries ([\#26228](https://github.com/facebook/react/pull/26228) by [@sophiebits](https://github.com/sophiebits)) * Fix logic around attribute serialization ([\#26526](https://github.com/facebook/react/pull/26526) by [@gnoff](https://github.com/gnoff)) * Fix precomputed chunk cleared on Node 18 ([\#25645](https://github.com/facebook/react/pull/25645) by [@feedthejim](https://github.com/feedthejim)) * Optimize end tag chunks ([\#27522](https://github.com/facebook/react/pull/27522) by [@yujunjung](https://github.com/yujunjung)) * Gracefully handle suspending in DOM configs ([\#26768](https://github.com/facebook/react/pull/26768) by [@sebmarkbage](https://github.com/sebmarkbage)) * Check for nullish values on ReactCustomFormAction ([\#26770](https://github.com/facebook/react/pull/26770) by [@sebmarkbage](https://github.com/sebmarkbage)) * Preload `bootstrapModules`, `bootstrapScripts`, and update priority queue ([\#26754](https://github.com/facebook/react/pull/26754), [\#26753](https://github.com/facebook/react/pull/26753), [\#27190](https://github.com/facebook/react/pull/27190), [\#27189](https://github.com/facebook/react/pull/27189) by [@gnoff](https://github.com/gnoff)) * Client render the nearest child or parent suspense boundary if replay errors or is aborted ([\#27386](https://github.com/facebook/react/pull/27386) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't bail out of flushing if we still have pending root tasks ([\#27385](https://github.com/facebook/react/pull/27385) by [@sebmarkbage](https://github.com/sebmarkbage)) * Ensure Resumable State is Serializable ([\#27388](https://github.com/facebook/react/pull/27388) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove extra render pass when reverting to client render ([\#26445](https://github.com/facebook/react/pull/26445) by [@acdlite](https://github.com/acdlite)) * Fix unwinding context during selective hydration ([\#25876](https://github.com/facebook/react/pull/25876) by [@tyao1](https://github.com/tyao1)) * Stop flowing and then abort if a stream is cancelled ([\#27405](https://github.com/facebook/react/pull/27405) by [@sebmarkbage](https://github.com/sebmarkbage)) * Pass cancellation reason to abort ([\#27536](https://github.com/facebook/react/pull/27536) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add `onHeaders` entrypoint option ([\#27641](https://github.com/facebook/react/pull/27641), [\#27712](https://github.com/facebook/react/pull/27712) by [@gnoff](https://github.com/gnoff)) * Escape `<style>` and `<script>` textContent to enable rendering inner content without dangerouslySetInnerHTML ([\#28870](https://github.com/facebook/react/pull/28870), [\#28871](https://github.com/facebook/react/pull/28871) by [@gnoff](https://github.com/gnoff)) * Fallback to client replaying actions for Blob serialization ([\#28987](https://github.com/facebook/react/pull/28987) by [@sebmarkbage](https://github.com/sebmarkbage)) * Render Suspense fallback if boundary contains new stylesheet during sync update ([\#28965](https://github.com/facebook/react/pull/28965) by [@gnoff](https://github.com/gnoff)) * Fix header length tracking (\#30327 by [@gnoff](https://github.com/gnoff)) * Use `srcset` to trigger load event on mount (\#30351 by [@gnoff](https://github.com/gnoff)) * Don't perform work when closing stream (\#30497 by [@gnoff](https://github.com/gnoff)) * Allow aborting during render (\#30488, [\#30730](https://github.com/facebook/react/pull/30730) by [@gnoff](https://github.com/gnoff)) * Start initial work immediately (\#31079 by [@gnoff](https://github.com/gnoff)) * A transition flowing into a dehydrated boundary no longer suspends when showing fallback ([\#27230](https://github.com/facebook/react/pull/27230) by [@acdlite](https://github.com/acdlite)) * Fix selective hydration triggers false update loop error ([\#27439](https://github.com/facebook/react/pull/27439) by [@acdlite](https://github.com/acdlite)) * Warn for Child Iterator of all types but allow Generator Components ([\#28853](https://github.com/facebook/react/pull/28853) by [@sebmarkbage](https://github.com/sebmarkbage)) * Include regular stack trace in serialized errors ([\#28684](https://github.com/facebook/react/pull/28684), [\#28738](https://github.com/facebook/react/pull/28738) by [@sebmarkbage](https://github.com/sebmarkbage)) * Aborting early no longer infinitely suspends ([\#24751](https://github.com/facebook/react/pull/24751) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix hydration warning suppression in text comparisons ([\#24784](https://github.com/facebook/react/pull/24784) by [@gnoff](https://github.com/gnoff)) * Changes to error handling in SSR
* Add diffs to hydration warnings ([\#28502](https://github.com/facebook/react/pull/28502), [\#28512](https://github.com/facebook/react/pull/28512) by [@sebmarkbage](https://github.com/sebmarkbage)) * Make Error creation lazy ([\#24728](https://github.com/facebook/react/pull/24728) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove recoverable error when a sync update flows into a dehydrated boundary ([\#25692](https://github.com/facebook/react/pull/25692) by [@sebmarkbage](https://github.com/sebmarkbage)) * Don't "fix up" mismatched text content with suppressedHydrationWarning ([\#26391](https://github.com/facebook/react/pull/26391) by [@sebmarkbage](https://github.com/sebmarkbage)) * Fix component stacks in errors ([\#27456](https://github.com/facebook/react/pull/27456) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add component stacks to `onError` ([\#27761](https://github.com/facebook/react/pull/27761), [\#27850](https://github.com/facebook/react/pull/27850) by [@gnoff](https://github.com/gnoff) and [@sebmarkbage](https://github.com/sebmarkbage)) * Throw hydration mismatch errors once ([\#28502](https://github.com/facebook/react/pull/28502) by [@sebmarkbage](https://github.com/sebmarkbage)) * Add Bun streaming server renderer ([\#25597](https://github.com/facebook/react/pull/25597) by [@colinhacks](https://github.com/colinhacks)) * Add nonce support to bootstrap scripts ([\#26738](https://github.com/facebook/react/pull/26738) by [@danieltott](https://github.com/danieltott)) * Add `crossorigin` support to bootstrap scripts ([\#26844](https://github.com/facebook/react/pull/26844) by [@HenriqueLimas](https://github.com/HenriqueLimas)) * Support `nonce` and `fetchpriority` in preload links ([\#26826](https://github.com/facebook/react/pull/26826) by [@liuyenwei](https://github.com/liuyenwei)) * Add `referrerPolicy` to `ReactDOM.preload()` ([\#27096](https://github.com/facebook/react/pull/27096) by [@styfle](https://github.com/styfle)) * Add server condition for `react/jsx-dev-runtime` ([\#28921](https://github.com/facebook/react/pull/28921) by [@himself65](https://github.com/himself65)) * Export version ([\#29596](https://github.com/facebook/react/pull/29596) by [@unstubbable](https://github.com/unstubbable)) * Rename the secret export of Client and Server internals ([\#28786](https://github.com/facebook/react/pull/28786), [\#28789](https://github.com/facebook/react/pull/28789) by [@sebmarkbage](https://github.com/sebmarkbage)) * Remove layout effect warning on server ([\#26395](https://github.com/facebook/react/pull/26395) by [@rickhanlonii](https://github.com/rickhanlonii)) * Remove `errorInfo.digest` from `onRecoverableError` ([\#28222](https://github.com/facebook/react/pull/28222) by [@gnoff](https://github.com/gnoff))
== ReactTestRenderer
* Add deprecation error to `react-test-renderer` on web ([\#27903](https://github.com/facebook/react/pull/27903), [\#28904](https://github.com/facebook/react/pull/28904) by [@jackpope](https://github.com/jackpope) and [@acdlite](https://github.com/acdlite)) * Render with ConcurrentRoot on web ([\#28498](https://github.com/facebook/react/pull/28498) by [@jackpope](https://github.com/jackpope)) * Remove `react-test-renderer/shallow` export ([\#25475](https://github.com/facebook/react/pull/25475), [\#28497](https://github.com/facebook/react/pull/28497) by [@sebmarkbage](https://github.com/sebmarkbage) and [@jackpope](https://github.com/jackpope))
== React Reconciler
* Enable suspending commits without blocking render ([\#26398](https://github.com/facebook/react/pull/26398), [\#26427](https://github.com/facebook/react/pull/26427) by [@acdlite](https://github.com/acdlite)) * Remove `prepareUpdate` ([\#26583](https://github.com/facebook/react/pull/26583), [\#27409](http://github.com/facebook/react/pull/27409) by [@sebmarkbage](https://github.com/sebmarkbage) and [@sophiebits](https://github.com/sophiebits))
== React-Is
* Enable tree shaking ([\#27701](https://github.com/facebook/react/pull/27701) by [@markerikson](https://github.com/markerikson)) * Remove `isConcurrentMode` and `isAsyncMode` methods ([\#28224](https://github.com/facebook/react/pull/28224) by @gaearon)
== useSyncExternalStore
* Remove React internals access ([\#29868](https://github.com/facebook/react/pull/29868) by [@phryneas](https://github.com/phryneas)) * Fix stale selectors keeping previous store references ([\#25969](https://github.com/facebook/react/pull/25968) by [@jellevoost](https://github.com/jellevoost))
@types/react and @types/react-dom are published from DefinitelyTyped
and have no changelog.
Release notes:
- https://github.com/facebook/react/blob/main/CHANGELOG.md
- React 19 upgrade guide: https://react.dev/blog/2024/04/25/react-19-upgrade-guide
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

15 participants

@sebmarkbage@react-sizebot@jschauma@justinrest@szybnev@rickhanlonii@matija2209@macropin@eps1lon@AlexDev404@DogRespector93@unstubbable@gnoff@KernelDeimos@galqbineva27-collab