Skip to content

@module-federation/bridge-react-webpack-plugin package contains unit tests #4256

@JPK64

Description

@JPK64

Describe the bug

Hello.

The npm package mentioned above seems to include a __tests__ directory which probably should not be there.

Unfortunately, this leads our build analysis tool to flag that package as containing CVE-2025-43865 because of a supposed react-router 7.0.0 dependency due to the package.json included in the __tests__/mockRouterDir/router-v7/react-router directory having that as the version.

Reproduction

Look at the @module-federation/bridge-react-webpack-plugin npm package at version 0.21.6

Used Package Manager

npm

System Info

Should not be relevant here.

Validations

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions