Skip to content

Update to react 19 - #5474

Merged
greenbonebot merged 3 commits into
mainfrom
update-to-react-19
Aug 6, 2026
Merged

Update to react 19#5474
greenbonebot merged 3 commits into
mainfrom
update-to-react-19

Conversation

@daniele-mng

@daniele-mng daniele-mng commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

What

Update to react 19

Why

References

GEA-1998

Checklist

  • Tests

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA ac6d3a5.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@dnd-kit/accessibility 3.1.1 🟢 5.8
Details
CheckScoreReason
Code-Review🟢 6Found 9/13 approved changesets -- score normalized to 6
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@dnd-kit/core 6.3.1 🟢 5.8
Details
CheckScoreReason
Code-Review🟢 6Found 9/13 approved changesets -- score normalized to 6
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@dnd-kit/modifiers 9.0.0 🟢 5.8
Details
CheckScoreReason
Code-Review🟢 6Found 9/13 approved changesets -- score normalized to 6
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@dnd-kit/sortable 10.0.0 🟢 5.8
Details
CheckScoreReason
Code-Review🟢 6Found 9/13 approved changesets -- score normalized to 6
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@dnd-kit/utilities 3.2.2 🟢 5.8
Details
CheckScoreReason
Code-Review🟢 6Found 9/13 approved changesets -- score normalized to 6
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@emotion/cache 11.14.0 🟢 5.6
Details
CheckScoreReason
Security-Policy🟢 4security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained⚠️ 10 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1
Code-Review🟢 8Found 17/20 approved changesets -- score normalized to 8
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@emotion/react 11.14.0 🟢 5.6
Details
CheckScoreReason
Security-Policy🟢 4security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained⚠️ 10 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1
Code-Review🟢 8Found 17/20 approved changesets -- score normalized to 8
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@emotion/use-insertion-effect-with-fallbacks 1.2.0 🟢 5.6
Details
CheckScoreReason
Security-Policy🟢 4security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained⚠️ 10 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1
Code-Review🟢 8Found 17/20 approved changesets -- score normalized to 8
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@floating-ui/core 1.8.0 UnknownUnknown
npm/@floating-ui/dom 1.8.0 UnknownUnknown
npm/@floating-ui/react 0.27.20 UnknownUnknown
npm/@floating-ui/react-dom 2.1.9 UnknownUnknown
npm/@floating-ui/utils 0.2.12 UnknownUnknown
npm/@greenbone/ui-lib 2.13.6-alpha0 UnknownUnknown
npm/@tanstack/react-table 8.21.3 UnknownUnknown
npm/@tanstack/table-core 8.21.3 UnknownUnknown
npm/@types/react 19.2.18 🟢 6.6
Details
CheckScoreReason
Code-Review🟢 9Found 28/29 approved changesets -- score normalized to 9
Maintained🟢 1030 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
License🟢 9license file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/@types/react-dom 19.2.4 🟢 6.6
Details
CheckScoreReason
Code-Review🟢 9Found 28/29 approved changesets -- score normalized to 9
Maintained🟢 1030 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
License🟢 9license file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/@types/react-is 19.2.0 🟢 6.6
Details
CheckScoreReason
Code-Review🟢 9Found 28/29 approved changesets -- score normalized to 9
Maintained🟢 1030 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
License🟢 9license file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/react 19.2.8 UnknownUnknown
npm/react-dom 19.2.8 UnknownUnknown
npm/react-is 19.2.8 UnknownUnknown
npm/react-number-format 5.4.5 🟢 3.8
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Code-Review⚠️ 2Found 5/18 approved changesets -- score normalized to 2
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/scheduler 0.27.0 UnknownUnknown
npm/tabbable 6.5.0 🟢 5.2
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Code-Review⚠️ 0Found 0/1 approved changesets -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • package-lock.json

@daniele-mng
daniele-mng force-pushed the update-to-react-19 branch 3 times, most recently from 6bd1c81 to 931f1c4 Compare August 5, 2026 05:58
@daniele-mng
daniele-mng marked this pull request as ready for review August 6, 2026 11:17
@daniele-mng
daniele-mng requested a review from a team as a code owner August 6, 2026 11:17
@greenbonebot
greenbonebot enabled auto-merge (rebase) August 6, 2026 11:17
@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 50.00000% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.82%. Comparing base (03c83fd) to head (ac6d3a5).

Files with missing lines Patch % Lines
src/web/components/chart/donut/Pie.tsx 0.00% 3 Missing ⚠️
src/web/components/chart/Donut.tsx 0.00% 2 Missing ⚠️
src/web/components/chart/HostsTopologyChart.tsx 0.00% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #5474      +/-   ##
==========================================
- Coverage   81.85%   81.82%   -0.03%     
==========================================
  Files        1284     1284              
  Lines       33680    33688       +8     
  Branches    10027    10030       +3     
==========================================
- Hits        27569    27566       -3     
- Misses       5453     5462       +9     
- Partials      658      660       +2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@greenbonebot
greenbonebot merged commit a02c821 into main Aug 6, 2026
26 of 28 checks passed
@greenbonebot
greenbonebot deleted the update-to-react-19 branch August 6, 2026 15:59
@nikhilgosavi007
nikhilgosavi007 requested a lite review from Copilot August 18, 2026 09:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the web frontend to React 19 (and corresponding @types/* packages) and applies a set of TypeScript/ref-typing adjustments plus test updates to align with React 19 + updated typings behavior.

Changes:

  • Upgrade react, react-dom, react-is, and React type packages to React 19 versions; update @greenbone/ui-lib.
  • Update ref-related typings/usages (e.g., RefObject<... | null>, callback refs) and element cloning typings.
  • Adjust unit tests to match updated React rendering / mock-call semantics and timing.

Reviewed changes

Copilot reviewed 27 out of 28 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
src/web/utils/Render.tsx Ref utility tweaks for React 19 (notably setRef).
src/web/utils/tests/withTranslation.test.tsx Test expectation updated for React 19 mock invocation behavior.
src/web/pages/vulnerabilities/dashboard/VulnerabilitiesHostsBarChart.tsx svgRef prop type updated to allow null.
src/web/pages/reports/AuditReportDetailsContent.tsx Removes a TS suppression around AuditThresholdPanel usage.
src/web/pages/reports/tests/ReportDetailsPage.test.tsx Test timing/queries updated (waitFor, role-based readiness).
src/web/pages/reports/tests/AuditReportDetailsPage.test.tsx Test timing/queries updated (waitFor, role-based readiness).
src/web/pages/policies/PoliciesComponent.tsx Adds explicit props to PolicyDialog usage for typing compatibility.
src/web/pages/hosts/tests/HostComponent.test.tsx Updates HostsDialog test render with newly-required/typed props.
src/web/pages/hosts/tests/Dialog.test.tsx Updates HostsDialog tests with newly-required/typed props.
src/web/pages/audits/DetailsPage.tsx Adds missing callback props to AuditComponent.
src/web/hooks/usePreviousValue.ts Makes useRef initialization explicit for React 19 typings.
src/web/entity/tests/Tags.test.tsx Updates EntityTags tests with required callbacks.
src/web/entities/tests/withEntitiesFooter.test.tsx Test expectation updated for React 19 mock invocation behavior.
src/web/entities/tests/withEntitiesActions.test.tsx Test expectation updated for React 19 mock invocation behavior.
src/web/components/tab/Tabs.tsx Tightens cloneElement typing for React 19.
src/web/components/info-tip/ComponentWithInfoTip.tsx Tightens slot typing and refactors slot.props access.
src/web/components/hover-card/ComponentWithHoverCard.tsx Tightens slot typing and refactors slot.props access.
src/web/components/form/ToggleButton.tsx Avoids onToggle collision with intrinsic HTML attribute typing.
src/web/components/form/Download.tsx Ref callback made block-bodied (style/typing alignment).
src/web/components/dashboard/display/DataDisplay.tsx Ref types updated to allow null.
src/web/components/chart/HostsTopologyChart.tsx Callback ref updated to block-bodied (style/typing alignment).
src/web/components/chart/donut/Pie.tsx Default destructuring values adjusted (likely for typing consistency).
src/web/components/chart/Donut.tsx Ref wiring updated to align with ref typing changes.
src/web/components/chart/base/Tooltip.tsx Ref object types updated to allow null.
src/web/components/chart/base/Line.tsx Ref typing updated to allow null.
src/web/components/chart/base/Legend.tsx LegendRef type updated to allow null.
package.json React 19 + related dependency/version updates.
package-lock.json Lockfile updates reflecting the dependency upgrades.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/web/utils/Render.tsx
Comment on lines 573 to 577
if (isFunction(rf)) {
(rf as React.RefCallback<TRef>)(ref);
} else if (isObject(rf) && isDefined(rf.current)) {
// @ts-expect-error
(rf as React.RefObject<TRef>).current = ref;
}
Comment on lines +63 to 66
title: slotProps.title ? (
<>
{slot.props.title}
{slotProps.title}
{infoTipElement}
Comment on lines +58 to 61
title: slotProps.title ? (
<>
{slot.props.title}
{slotProps.title}
{hoverCardElement}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants