Dashboard › spotlight › react-router-dom has no 8.x — advisory …
019fa880-e888-7807-b993-fb3b9f6ddc64Trap: Dependabot alert #322 (react-router RSC CSRF, GHSA-qwww-vcr4-c8h2, range >=7.12.0 <8.3.0) looks fixable by bumping react-router-dom to 8.3.0. But react-router-dom has NO 8.x published on npm (latest is 7.18.1); only the core react-router package has 8.x. So react-router-dom@7.18.1 remains vulnerable to #322. The vuln only affects unstable RSC APIs, which getsentry/spotlight does NOT use (it uses BrowserRouter/HashRouter SPA mode). Fix: dismiss #322 as not-applicable/won't-fix and flag in PR; revisit only if react-router-dom@8.x ships.