Skip to content
CAI
Software that uses CAICheck a score

remix-run/react-router

49.2

Weak · 28 September 2026

54.8k

lines of production code

TypeScript

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the React Router framework, providing a comprehensive routing solution for React applications with support for server-side rendering, static site generation, and React Server Components. It includes platform-specific adapters for Node.js, Express, AWS API Gateway, and Cloudflare Workers, enabling deployment across diverse hosting environments. The framework features a modern Vite-based development tooling ecosystem, programmatic and file-system-based route configuration, and robust session management strategies.

How it got here

2014–2024 — React Router v8 framework and platform expansion

52 changes.

This period focused on the comprehensive development and stabilization of React Router v8, introducing a new Framework Mode with Server-Side Rendering, React Server Components support, and a 'Fog of War' lazy loading strategy. The work involved restructuring core packages, modernizing the build tooling with Vite 7/8, and expanding platform support through new adapters for Node.js, Cloudflare Workers, and AWS. Extensive test coverage and type system overhauls were implemented to ensure stability and type safety across these new features.

2025 — React Server Components integration

22 changes.

This period focused on introducing and stabilizing React Server Components (RSC) support within React Router, including core implementation, Vite plugin infrastructure, and HMR capabilities. It also expanded ecosystem integrations with new templates and playgrounds for Cloudflare Workers and middleware, alongside internal fixes to the turbo-stream library for robust data serialization.

2026 — v7 integration and release automation

13 changes.

This period focused on establishing the infrastructure for React Router v7, including updated Vite 7 integration templates, new playgrounds for data mode and RSC, and performance benchmarks. It also introduced a comprehensive internal release automation system, replacing external tools with custom scripts for changelog generation, PR previews, and CI workflows.

Features

Add Arc Table session storage for AWS DynamoDB

Users can now persist React Router sessions in an AWS DynamoDB table managed by Architect. The new \createArcTableSessionStorage\ function allows configuring a specific DynamoDB table (via name or object), the partition key attribute, and an optional TTL attribute for automatic session expiration, providing a scalable server-side session store option.

packages/react-router-architect/sessions · high confidence

Add data mode playground

A new playground example has been added at playground/data that demonstrates React Router's data mode. It provides a minimal setup using Vite and TypeScript to showcase server-side data loading via loaders and the useLoaderData hook, allowing users to experiment with this specific routing pattern.

playground/data · high confidence

Add file-based session storage for Node.js

A new \createFileSessionStorage\ function is now available in the \react-router-node\ package, allowing developers to store session data on the local filesystem instead of relying solely on cookies. This implementation generates unique session IDs, writes session data to JSON files in a specified directory, and automatically cleans up expired sessions, providing a scalable alternative for storing larger amounts of session data.

packages/react-router-node/sessions · high confidence

Add playground demos for route module splitting

Added two new playground applications, \split-route-modules\ and \split-route-modules-spa\, that demonstrate React Router's route module splitting capabilities. These demos include route definitions for splittable, unsplittable, and semi-splittable scenarios, along with client loaders and actions to illustrate how code splitting behaves in different contexts. The \split-route-modules-spa\ variant is configured as a single-page application (SSR disabled), while the standard \split-route-modules\ playground retains server-side rendering support.

playground/split-route-modules, playground/split-route-modules-spa · high confidence

Add playground for \`vite-plugin-cloudflare\`

A new playground environment has been added for the \vite-plugin-cloudflare\ package, providing a reference implementation for integrating React Router with Cloudflare Workers. This setup includes a Vite configuration that utilizes the \@cloudflare/vite-plugin\ with the Vite environment API for SSR, a React Router application structure, and a \wrangler.toml\ file to define the Cloudflare Worker entry point and environment variables.

playground/vite-plugin-cloudflare, playground/vite-plugin-cloudflare/workers · high confidence

Added HMR/HDR support for React Server Components

The Vite development server now supports Hot Module Replacement (HMR) and Hot Data Revalidation (HDR) for React Server Components (RSC). New runtime utilities injected into the browser handle route updates and component refreshes specifically for the RSC framework mode, allowing developers to see changes to server components and their associated data loaders without a full page reload.

packages/react-router-dev/vite/static · high confidence

Expanded RSC playground with new route demonstrations

The RSC framework playground now includes a broader set of route examples to demonstrate React Server Components capabilities. This update adds routes for server-side actions, client-side loaders (with and without server loaders), and optimistic UI updates using React's useOptimistic hook. It also introduces comprehensive MDX support, featuring glob-based imports for dynamic blog posts and direct MDX route definitions, alongside standard server loader and layout examples.

playground/rsc-vite-framework/app/routes · high confidence

Initial RSC Framework Mode playground setup

The RSC playground now includes the core application entry points (entry.client.tsx, entry.rsc.tsx, entry.ssr.tsx) and root layout (root.tsx) required to run the new RSC framework mode. This setup enables React Server Components hydration, server-side rendering, and client-side navigation within the playground environment.

playground/rsc-vite-framework/app · high confidence

Introduce @react-router/architect for AWS API Gateway integration

This release adds the \@react-router/architect\ package, providing a server request handler specifically designed for AWS API Gateway (Architect). It exposes \createRequestHandler\ to bridge React Router with AWS Lambda events, automatically handling host derivation from the request context, cookie parsing, and binary content encoding (base64) for supported MIME types. The package also includes \createArcTableSessionStorage\ for session management and requires a minimum Node version of 22.22.0.

packages/react-router-architect · high confidence

Introduce @react-router/cloudflare package for Cloudflare Workers

Adds a new \@react-router/cloudflare\ package that provides platform-specific abstractions for deploying React Router applications on Cloudflare Workers. This includes \createPagesFunctionHandler\ and \createRequestHandler\ to integrate React Router with the Cloudflare Workers runtime, support for Cloudflare KV-based session storage via \createWorkersKVSessionStorage\, and proper binding of Cloudflare-specific context features like \waitUntil\ and \passThroughOnException\.

packages/react-router-cloudflare · high confidence

Introduce @react-router/fs-routes package for file-system-based routing

The new \@react-router/fs-routes\ package provides a \flatRoutes\ function that generates a React Router route configuration from file-system conventions (matching Remix v2 style). It scans the app's routes directory, resolves route IDs and paths, handles nested parent-child relationships, and supports ignoring specific files via minimatch globs. The package also enforces that a root route module and the routes directory exist, throwing clear errors if they are missing.

packages/react-router-fs-routes · high confidence

Introduce @react-router/node package with streaming and request handling

The new \@react-router/node\ package provides Node.js platform abstractions for React Router, including \createRequestListener\ for handling HTTP requests and stream utilities (\writeReadableStreamToWritable\, \writeAsyncIterableToWritable\) that properly honor Node writable backpressure and prevent memory leaks or crashes during long-running streams.

packages/react-router-node · high confidence

Introduce RSC Framework Mode for React Router

Adds a new RSC (React Server Components) Framework Mode to the React Router Vite plugin, enabling server-first rendering with support for server components, client actions/loaders, and HMR. This mode includes dedicated handling for route configuration, virtual route modules, and optimized dependency scanning, while validating unsupported legacy configurations like \serverBundles\ and \presets\.

packages/react-router-dev/vite/rsc · high confidence

Introduce RSC Framework Mode playground with Vite middleware and MDX support

The playground/rsc-vite-framework location now provides a concrete demonstration of the new RSC Framework Mode, featuring a Vite-based setup that supports middleware mode for development and static prerendering for production. This entry point includes configuration for route module splitting, TypeScript declarations for MDX imports, and a custom entry file structure, allowing users to experiment with React Server Components in a Vite environment alongside standard React Router features.

playground/rsc-vite-framework · high confidence

Introduce React Router DOM subpath exports for SSR hydration

React Router now exposes a dedicated \react-router/dom\ subpath export containing the \RouterProvider\ and \HydratedRouter\ components. The \RouterProvider\ in this subpath wraps the base provider to inject \ReactDOM.flushSync\, ensuring synchronous updates during hydration. The \HydratedRouter\ component handles the client-side initialization for Server-Side Rendering (SSR) by decoding the initial state from a TurboStream, supporting both standard SSR and SPA mode, and managing the transition from server-rendered HTML to a fully interactive client router.

packages/react-router/lib/dom-export · high confidence

Introduce React Router Framework Mode with ServerRouter and Fog of War

This change introduces the core server-side rendering (SSR) and hydration components for the new React Router Framework Mode. It adds the \ServerRouter\ component, which serves as the entry point for server-side HTML generation, and the \FrameworkContext\ to pass manifest and route module data to the client. The update implements the 'Fog of War' lazy route discovery mechanism to prefetch and patch route modules on demand, improving initial load performance. Additionally, it establishes the 'Single Fetch' data strategy for efficient client-server data synchronization and provides default error boundaries and hydrate fallbacks to ensure robust application shells during SSR and hydration.

packages/react-router/lib/dom/ssr · high confidence

Introduce React Server Components (RSC) Router implementation

This change introduces the core React Server Components (RSC) router implementation within the \packages/react-router/lib/rsc\ directory. It adds the \browser.tsx\ module for client-side call server handling and hydration, \server.rsc.ts\ for server-side route configuration and action handling, \server.ssr.tsx\ for routing server requests and rendering HTML, and \errorBoundaries.tsx\ for global error handling. These files collectively provide the foundational infrastructure for React Router to support the RSC architecture, including payload decoding, server action execution, and error boundary management.

packages/react-router/lib/rsc · high confidence

Introduce Remix routes config adapter

The new \@react-router/remix-routes-option-adapter\ package allows developers to define routes using Remix's \routes\ config option (via \defineRoutes\) within a \routes.ts\ file. This adapter translates the Remix-style route manifest into React Router's configuration format, enabling seamless integration of Remix-style route definitions into React Router applications.

packages/react-router-remix-routes-option-adapter · high confidence

Introduce create-react-router CLI with native dependencies and agent skill support

The \create-react-router\ package is now a standalone CLI tool for scaffolding new React Router applications. It replaces external dependencies like \arg\, \strip-ansi\, and \execa\ with native Node.js utilities for argument parsing, ANSI stripping, and child process execution. New projects include the official React Router agent skill by default (configurable via \--no-agent-skills\), and the tool now detects the \nub\ package manager in addition to existing options like Deno.

packages/create-react-router · high confidence

Introduce programmatic route configuration via \`routes.ts\`

Developers can now define their application's route structure programmatically by exporting an array of route entries from an \app/routes.ts\ file. This new configuration method is validated against a strict schema (using Valibot) that enforces correct types and prevents reserved identifiers like 'root'. The system provides helper utilities to construct these entries and supports formatting the resulting manifest as either JSON or JSX, offering an alternative to file-system-based route discovery.

packages/react-router-dev/config · high confidence

New Cloudflare template for React Router

A new starter template for React Router applications targeting Cloudflare Workers has been added to the integration helpers. This template provides a complete project structure including a Vite configuration that integrates the Cloudflare Vite plugin with SSR environment support, a Wrangler configuration for Workers deployment, and specific TypeScript configurations to handle Cloudflare's runtime types and environment variables.

integration/helpers/vite-plugin-cloudflare-template · high confidence

New Express-based React Router playground

Added a new playground located at playground/framework-express that demonstrates a React Router application running on an Express server. This includes the necessary configuration files (tsconfig.json, vite.config.ts, react-router.config.ts), a server entry point (server.js) using @react-router/express, and standard app structure files (root.tsx, routes.ts, index route).

playground/framework-express · high confidence

New RSC + Vite 7 framework playground with comprehensive route and loader examples

This change introduces a new \playground/rsc-vite-7-framework\ application that demonstrates React Server Components (RSC) with Vite 7. The playground includes a full application structure with a root layout, navigation, and error boundaries. It showcases various React Router features including server loaders, client loaders (with and without server loaders), client loader hydration, and optimistic UI updates via server actions. It also includes MDX support with glob-based route generation and component imports, as well as nested layouts. The setup uses \@react-router/dev/vite\ and \@vitejs/plugin-rsc\ for the build configuration.

playground/rsc-vite-7-framework · high confidence

New RSC Vite integration helper scaffolding

The \integration/helpers/rsc-vite\ directory now provides a complete scaffolding for React Server Components with Vite, replacing the previous \@hiogawa/vite-rsc\ setup with \@vitejs/plugin-rsc\. This helper includes a Node/Express server entry point, Vite configuration defining client, RSC, and SSR entry points, and route definitions supporting features like basename configuration, request context, and form state hydration via the \react-router/dom\ unstable APIs.

integration/helpers/rsc-vite · high confidence

New RSC Vite playground with official plugin integration

Added a new playground example at playground/rsc-vite that demonstrates React Server Components using the official @vitejs/plugin-rsc. The setup includes a Vite configuration defining client, RSC, and SSR entry points, a TypeScript configuration extending the base project settings, and a Node.js Express server that serves the static client assets and handles RSC requests via @remix-run/node-fetch-server.

playground/rsc-vite · high confidence

New React Router address-book tutorial

A new tutorial project named 'address-book' has been added to the tutorials directory, demonstrating a React Router application setup. The project includes configuration for Vite and React Router (with SSR disabled), a TypeScript configuration targeting ES2022, and standard development/deployment instructions in the README.

tutorials · high confidence

React Router now provides built-in session storage strategies via \createCookieSessionStorage\ and \createMemorySessionStorage\. The cookie-based storage persists session data directly within the client-side cookie, eliminating the need for external databases but subject to browser size limits, while the in-memory storage is designed for local development and testing, using \crypto.randomUUID\ for session IDs and discarding data on server restart.

packages/react-router/lib/server-runtime/sessions · high confidence

New framework and SPA playgrounds for React Router

Two new playgrounds have been added to demonstrate React Router capabilities: a Single-Page Application (SPA) example and a full-stack framework example. The SPA playground provides a minimal setup with client-side rendering, while the framework playground demonstrates server-side rendering with loaders, route definitions, and prefetching. Both include standard configuration files for Vite, TypeScript, and React Router, offering developers starting templates for building applications with the framework.

playground/framework · high confidence

New middleware playground demonstrating server and client context APIs

A new \playground/middleware\ example has been added to demonstrate the stabilized Middleware and Context APIs. It showcases how to define server-side (\middleware\) and client-side (\clientMiddleware\) route functions that share state via a \RouterContextProvider\. The example includes a custom Express server setup (\server.ts\, \dev-server.ts\) that injects an \expressContext\ into the React Router context, allowing routes to read and propagate context values (such as 'ROOT', 'A', 'B') through both server loaders and client loaders.

playground/middleware · high confidence

New performance playground with route-matching benchmark

A new playground located at playground/performance has been added to help evaluate React Router's server-side performance. It includes a pre-configured React Router application with a comprehensive set of 100 static and dynamic routes (covering areas like admin, commerce, and user profiles) to simulate a complex application structure. Additionally, a benchmark script (scripts/bench.mjs) is provided, allowing users to measure server throughput and latency (mean, p50, p95, p99) by sending concurrent requests against this route set.

playground/performance · high confidence

New release, documentation, and maintenance automation scripts

The repository now includes a suite of new scripts to automate the release lifecycle and documentation generation. The \scripts/experimental.ts\ script enables the creation and publishing of experimental releases, while \scripts/release-comments.ts\ automates PR and issue notifications for new versions. Documentation is now generated via \scripts/docs.ts\ using TypeDoc, and \scripts/change-file-check.ts\ enforces that source changes are accompanied by changelog entries. Maintenance is supported by \scripts/delete-nightly-tags.sh\ and \scripts/delete-pre-tags.sh\ for tag cleanup, and \scripts/playground.js\ allows developers to easily copy and run local playground templates.

scripts · high confidence

New scripts to automate PR preview builds and installation

Added two new scripts in \scripts/previews/\ to streamline the creation and management of installable preview builds for pull requests. The \branch.ts\ script prepares a base branch (e.g., \main\) by building the project, adjusting \.gitignore\, and updating internal \@react-router/\*\ dependencies to point to a specific GitHub branch, enabling direct installation via \pnpm install\. The \pr.ts\ script automates the PR workflow by adding or updating a sticky comment with installation instructions for the preview build and handling cleanup (deleting the branch and posting a notification) when the PR is merged or closed.

scripts/previews · high confidence

Repository initialization and development environment setup

The repository has been initialized with a comprehensive development environment configuration. This includes a \.browserslistrc\ file defining supported browser versions (Chrome \>= 73, Firefox \>= 67, Edge \>= 17, Safari \>= 12.1, iOS \>= 11.3), a \.nvmrc\ file pinning the Node.js version to 24, and \.npmrc\ settings enabling workspace cycle detection and pre/post scripts. Standard project files such as \.gitignore\, \.gitattributes\, \.prettierignore\, \LICENSE.md\, \CODE\_OF\_CONDUCT.md\, \CONTRIBUTING.md\, \DEVELOPMENT.md\, \GOVERNANCE.md\, \CHANGELOG.md\, \AGENTS.md\, and \CLAUDE.md\ have been added to establish project standards, release processes, and contribution guidelines.

(repo-wide) · high confidence

Ship documentation files with the npm package

The build process now includes a script that copies a curated subset of the repository's documentation into the package's \docs/\ directory during the build step. This makes the documentation files available via the \react-router/docs/...\ package exports, enabling AI coding agents and React Router agent skills to access the docs directly from the installed package.

packages/react-router/scripts · high confidence

Support for Content Security Policy nonces in RSC HTML streaming

The React Server Components (RSC) HTML streaming implementation now supports Content Security Policy (CSP) nonces. When rendering the HTML stream on the server, the \injectRSCPayload\ function accepts an optional \nonce\ option, which is applied to the injected \\<script\>\ tags that deliver RSC data to the browser. This allows applications to comply with strict CSP policies that require nonces for inline scripts, ensuring that the RSC hydration data is executed correctly without being blocked by the browser's security policy.

packages/react-router/lib/rsc/html-stream · high confidence

Removals

Removal of legacy vendor libraries

The project has removed several legacy vendor libraries from the \vendor/\ directory, specifically JSXTransformer v0.9.0, jQuery v1.11.1, React v0.9.0, and Showdown.js. This change eliminates these bundled dependencies, likely reflecting a shift to modern alternatives or a different build strategy for these components.

vendor · high confidence

Security

Client-side CSRF protection for form actions

The router now validates the \origin\ header on client-side submissions to prevent Cross-Site Request Forgery attacks. When a form action is submitted, the router checks that the request's origin matches the current page's origin or is explicitly listed in the \allowedActionOrigins\ configuration. If the origins do not match and the origin is not allowed, the action is aborted with an error. This adds a security layer to data mutations initiated from the browser.

packages/react-router/lib · high confidence

Behavioural changes

Address Book tutorial updated for React Router v7

The address-book tutorial has been updated to align with the React Router v7 framework conventions. This includes adopting the new \root.tsx\ layout export pattern for the app shell, implementing the \routes.ts\ configuration file, and integrating a fake data layer using \match-sorter\ and \sort-by\ to simulate API interactions for the contact list.

tutorials/address-book · high confidence

Centralized Jest configuration for ESM and TypeScript support

The project now uses a shared Jest configuration (\jest.config.shared.js\) to standardize test execution across packages. This setup enables native ESM and TypeScript support by configuring \extensionsToTreatAsEsm\ and a custom Babel-based transformer, while mapping internal package aliases (such as \@react-router/dev\ and \react-router\) to their source locations. A new setup file ensures the \jest\ global is available, and development warnings are explicitly enabled via the \\_\DEV\\_\ flag.

jest · high confidence

Comprehensive type system overhaul for route data, middleware, and serialization

The type definitions in \packages/react-router/lib/types\ have been completely restructured to provide stricter, more accurate TypeScript support for React Router's data APIs. This change introduces a new \Register\ interface for app-wide type augmentation and a \Future\ interface to opt into future-flag-specific types. It replaces the previous \data\ property with \loaderData\ and \actionData\ in route module props and meta arguments, ensuring type safety for both server and client loaders. The diff adds robust serialization logic via the \unstable\_SerializesTo\ brand type, which correctly handles \ReadonlyMap\, \ReadonlySet\, and other container types when transporting data to the client. Additionally, it stabilizes the Middleware and Context APIs by defining precise types for \ServerDataFunctionArgs\ and \ClientDataFunctionArgs\, including proper handling of \RouterContextProvider\ and data strategy results, while removing deprecated types like \SerializeFrom\.

packages/react-router/lib/types · high confidence

Default RSC entry files now support formState, subresource integrity, and SSR hydration

The default React Server Components (RSC) entry files have been updated to improve progressive enhancement and security. The client entry (\entry.client.tsx\) now passes \formState\ to \hydrateRoot\, enabling proper hydration of forms with server-side state. The SSR entry (\entry.ssr.tsx\) supports subresource integrity via an import map and passes \formState\ to the stream renderer. The RSC server entry (\entry.rsc.tsx\) continues to handle server requests and HTML generation, integrating with the new SSR and client hydration flows.

packages/react-router-dev/config/default-rsc-entries · high confidence

Deprecate view transitions and fix route matching and docs

React Router's view transition APIs (including \viewTransition\ props, \useViewTransitionState\, and \NavLink\ transition props/classes) are deprecated in favor of React's native \\<ViewTransition\>\ component, with existing behavior unchanged. Additionally, \matchPath\ now correctly treats static segments as optional when they contain non-word characters, and the \unstable\_useRouterState\ documentation example has been corrected to use the imported alias.

packages/react-router/.changes · high confidence

Express adapter now respects proxy settings for host derivation and ignores writes after response close

The \@react-router/express\ adapter has been updated to correctly derive the request host when running behind a reverse proxy: it now reads the port from the \X-Forwarded-Host\ header if the Express \trust proxy\ setting is enabled, and sanitizes invalid hostname characters. Additionally, the adapter now ignores write operations after the Express response has closed, preventing errors from surfacing when a client disconnects before the response stream is fully destroyed or ended.

packages/react-router-express · high confidence

Inline turbo-stream v2 fork with Map/Set and error serialization fixes

The \packages/react-router/vendor\ directory now contains an inlined, custom fork of the \turbo-stream\ library (version 2). This change replaces the external dependency with local source files (\flatten.ts\, \unflatten.ts\, \turbo-stream.ts\, \utils.ts\) to allow React Router to control the encoding and decoding logic directly. The implementation includes specific fixes for the correct ordering of Map and Set instances during decoding, support for invalid Date objects, and adjusted internal error serialization logic to handle framework hydration errors more robustly. It also removes undocumented custom error serialization logic and ensures that recursion is avoided to support massive payloads.

packages/react-router/vendor · high confidence

Integration test helpers migrated to Playwright and Vite 7/8 templates

The integration test helper suite has been rewritten to use Playwright as the default testing framework and Vite 7/8 as the default build tooling. The new \fixtures.ts\ and \playwright-fixture.ts\ files provide a Playwright-based test context with utilities for managing temporary project directories, applying file edits, and executing commands, replacing the previous fixture creation logic. The \create-fixture.ts\ helper now defaults to the \vite-7-template\ and supports SPA mode and prerendering scenarios, while \vite.ts\ generates Vite configurations compatible with Vite 7 and 8, including support for RSC Framework Mode and Cloudflare presets. This change standardizes the test environment, ensuring integration tests run against the latest Vite versions and leverage Playwright's robust browser automation capabilities.

integration/helpers · high confidence

New CLI entry points and runtime detection logic

The \@react-router/dev\ package now exposes a structured CLI interface with dedicated entry points (\cli/index.ts\, \cli/run.ts\) and command implementations (\cli/commands.ts\). This update introduces a \detectPackageManager\ utility that identifies the user's package manager (npm, pnpm, yarn, bun, or nub) via environment variables, and adds a \--mode\ flag support to the \routes\ command to honor the development condition. The CLI also enforces a minimum Node.js version of 22.22.0, warning users if an older version is detected, and includes logic to generate runtime-specific server entries (web-streams vs. Node.js) based on project configuration.

packages/react-router-dev/cli · high confidence

New RSC playground routes demonstrate client-server data loading and middleware

The RSC Vite playground now includes a full set of route files (home, about, parent, child, root) that demonstrate the integration of React Server Components with React Router. These routes showcase client-side data mutation via \clientLoader\ and \clientAction\, server-side actions using the \'use server'\ directive, and the application of a global middleware function in the root route. The layout also includes error boundaries and navigation state reporting to illustrate the complete data flow and error handling capabilities in this mode.

playground/rsc-vite/src/routes · high confidence

New Vite plugin infrastructure for prerendering, plugin ordering, and source map warnings

The Vite plugin layer now includes dedicated support for prerendering, strict validation of plugin execution order, and warnings for insecure production configurations. A new prerender plugin allows users to define specific requests to pre-render during the build process, with configurable concurrency, retries, and post-processing hooks to generate static files. To ensure compatibility with React Server Components (RSC) and MDX, a validation plugin enforces that \@vitejs/plugin-rsc\ is placed after the React Router RSC plugin and that \@mdx-js/rollup\ is placed before the React Router plugin, throwing errors if these orderings are violated. Additionally, a new warning plugin alerts users if source maps are enabled in production builds, highlighting the security risk of exposing server code in the browser.

packages/react-router-dev/vite/plugins · high confidence

New local change-file workflow replaces changesets

The repository has replaced the external changesets tool with a new set of local scripts in scripts/changes. This introduces a new process for managing releases: developers create change files using scripts/changes/add.ts (which generates kebab-case slugs and strips common stop words), which are then validated by scripts/changes/validate.ts. The system supports migrating existing changeset files via scripts/changes/migrate-changesets.ts. Release preparation is handled by scripts/changes/version.ts (updating package.json and CHANGELOG.md) and scripts/changes/pr.ts (creating or updating the release PR with generated changelogs). Finally, scripts/changes/publish.ts handles the actual npm publishing and GitHub release creation, including support for v7-specific npm tags.

scripts/changes · high confidence

New release and CI utility scripts for the monorepo

The scripts/utils directory now includes a new set of TypeScript utilities to support the updated release process and CI workflows. These additions provide helpers for terminal colorization (color.ts), file system operations (fs.ts), and Git interactions such as tag resolution and PR number parsing (git.ts). Additionally, new modules handle GitHub API interactions for creating releases and managing pull requests (github.ts), monorepo package discovery and dependency mapping (packages.ts), and safe command execution with logging (process.ts). These tools replace the previous changeset-based workflow, enabling the new release automation and PR labeling features.

scripts/utils · high confidence

RSC playground adopts new Vite plugin and React Router APIs

The RSC playground has been updated to use the \@vitejs/plugin-rsc\ plugin (replacing the previous \@hiogawa/vite-rsc\) and integrates with React Router's unstable RSC APIs, including \routeRSCServerRequest\ and \RSCHydratedRouter\. This change enables support for passing \formState\ during hydration, allows throwing redirect responses at RSC render time, and ensures proper hot-module reloading via \import.meta.hot.accept\ in the RSC entry point.

playground/rsc-vite/src · high confidence

React Router Vite plugin refactored for Vite 7+ and ESM compatibility

The \packages/react-router-dev/vite\ package has been rewritten to support Vite 7+ (and Vite 8) and modern ESM-only environments. This change introduces a new \babel.ts\ module to handle Babel runtime compatibility across different Node.js versions, a \node-adapter.ts\ that uses \@remix-run/node-fetch-server\ to correctly handle \X-Forwarded-Proto\ for origin validation behind proxies, and a \remove-exports.ts\ module for dead-code elimination of unused route exports. The plugin now uses Vite's Environment API for builds and dev servers, and includes new CLI shortcuts (e.g., 'p' for profiling) and improved error handling for missing plugins.

packages/react-router-dev/vite · high confidence

React Router dev package restructured for v8 with new CLI and Vite integration

The \@react-router/dev\ package has been restructured for version 8, introducing a new CLI entry point (\bin.cjs\) that sets environment conditions and relaunches the process with specific flags. The package now exposes a Vite plugin (\reactRouterVitePlugin\) and an unstable RSC plugin, along with configuration helpers for route definitions (\routes.ts\). It also includes new virtual modules for RSC features like sub-resource integrity and client versioning, and updates dependencies such as Babel and Prettier.

packages/react-router-dev · high confidence

React Router v8 DOM package restructure and stabilization

The \packages/react-router/lib/dom\ module has been reorganized into distinct files (\dom.ts\, \global.ts\, \lib.tsx\, \server.tsx\) to support the v8 release. This change consolidates DOM-specific utilities (like \createSearchParams\ and form submission helpers), defines global window context types for hydration and manifest data, and exposes the core React components (\BrowserRouter\, \StaticRouter\, etc.) and hooks. It also stabilizes previously unstable APIs, removes legacy v7/v8 future flags, and updates the minimum supported React version to 19.2.6.

packages/react-router/lib/dom · high confidence

React Router v8 core router refactoring and stabilization

The \packages/react-router/lib/router\ module has been significantly restructured for the upcoming v8 release. This change introduces a new \RoutePatternDataRouteMatcher\ (with an optional preloading API) to replace the legacy regex-based matching, improving performance and correctness for route patterns. The router now supports a new \instrumentation\ API for tracing loaders, actions, and navigations, and stabilizes the \middleware\ and \dataStrategy\ APIs, removing previous future flags. Additionally, the \data\ property on router state is deprecated in favor of \loaderData\, and the \AppLoadContext\ has been removed in favor of a new \createContext\ utility for type-safe context passing.

packages/react-router/lib/router · high confidence

React Router v8 server-runtime consolidation and API stabilization

The server-side runtime logic has been consolidated into the \packages/react-router/lib/server-runtime\ directory, introducing a unified \ServerBuild\ interface and dedicated modules for cookies, sessions, and single-fetch handling. This change stabilizes the \dataStrategy\, \middleware\, and \context\ APIs while removing legacy future flags such as \v8\_middleware\, \v7\_throwAbortReason\, and \v7\_relativeSplatPath\. Cookie handling has been updated to use the \cookie-es\ library and the Web Crypto API for signing, and the framework now enforces stricter origin checks for actions to prevent CSRF attacks. Additionally, the server runtime now supports prerendering for resource routes, handles 304 responses correctly, and improves error sanitization in production modes.

packages/react-router/lib/server-runtime · high confidence

React Router v8.4.0 release with performance, stability, and RSC improvements

This release introduces several key updates for users. Performance is improved by switching to more granular internal router contexts to avoid unnecessary route component re-renders when unrelated data router state changes, though this involves breaking changes to exported \UNSAFE\_\ contexts. Stability is enhanced by preventing stale route discovery during manifest version-mismatch recovery, preserving lazy route module import errors during SPA navigations, and fixing issues with fetcher revalidation against splat routes. React Server Components (RSC) support is strengthened with fixes for correctly escaping streamed redirect locations in meta tag attributes, avoiding unintended \document.startViewTransition\ calls during hydration, and preserving RSC route component metadata to skip unnecessary server requests. Additionally, the \createStaticRouter({ branches })\ option is deprecated as route branches are now cached internally, and an unstable \future.unstable\_routePatternMatching\ flag is added for more efficient route matching.

packages/react-router · high confidence

Refactored typegen into a modular, context-driven architecture

The typegen system in \packages/react-router-dev/typegen\ has been restructured into distinct modules (\context.ts\, \generate.ts\, \index.ts\, \params.ts\, \route.ts\) to improve maintainability and separation of concerns. This change introduces a centralized \Context\ object that manages the configuration loader, root directory, and RSC mode state, which is now passed explicitly to generation functions. The route generation logic is split into specific helpers for parsing URL parameters, calculating route lineages and full paths, and producing TypeScript declarations for server builds, route pages, files, and modules. This modularization supports the underlying behavioral changes in type generation, such as handling virtual modules and dynamic segments, by isolating the logic for each aspect of the type output.

packages/react-router-dev/typegen · high confidence

Runtime-specific default server entry templates with improved streaming and HEAD support

The default server entry templates have been split into runtime-specific versions (Node and Web) to better match the underlying rendering APIs. The Node entry now uses \renderToPipeableStream\ with a configurable \streamTimeout\ (defaulting to 5 seconds) and explicitly handles HEAD requests by returning an empty body, addressing previous memory leak concerns. The Web entry utilizes \renderToReadableStream\ with an abort signal for timeout management. Both templates ensure that bot and SPA mode requests wait for full content readiness before responding, while client-side hydration defaults to using \hydrateRoot\ within a \StrictMode\ wrapper.

packages/react-router-dev/config/defaults · high confidence

Serve dotfiles and support RSC framework mode

The \react-router-serve\ package now correctly serves \/.well-known/\*\ files (such as ACME challenges and assetlinks.json) from the client build directory, fixing a regression where Express 5's static middleware ignored dot-segment paths. It also adds support for React Server Components (RSC) Framework Mode, allowing the server to detect and handle custom entry files and RSC-specific configurations via \unstable\_reactRouterServeConfig\.

packages/react-router-serve · high confidence

Updated Vite 7 integration templates and playground to use React Router v7 conventions

The Vite 7 integration helper template and the framework-vite-7 playground have been updated to reflect React Router v7 patterns. The helper template now uses the \@react-router/fs-routes\ package for file-based routing configuration, while the playground demonstrates explicit route definitions using the \index\ and \route\ helpers from \@react-router/dev/routes\. Additionally, the playground's route components now utilize the new \Route.LoaderArgs\ and \Route.ComponentProps\ types for type-safe data loading and rendering, and the playground's root layout includes navigation links with \prefetch="intent"\ to showcase improved prefetching behavior.

integration/helpers/vite-7-template, playground/framework-vite-7 · high confidence

Fixes

Preserve source maps in RSC route transforms

The React Router development tooling now correctly preserves source maps for route modules when using the unstable RSC (React Server Components) Framework Mode. This ensures that debugging and error reporting remain accurate and traceable to the original source files during development.

packages/react-router-dev/.changes · high confidence

Test coverage

Add Cloudflare Workers template for Vite plugin integration testing; Add integration tests for RSC no-JS, prerendering, and error handling; Added basic test fixture for react-router-dev; Added benchmark for passThroughRequests flag; Added comprehensive test coverage for React Router core components and behaviors; Added integration tests for the create-react-router CLI; Added server-runtime test suite; Added test fixtures for the new create-react-router CLI template; Added test utilities for React Router testing; Added test utility functions for CLI execution and app fixture management; Added tests for Node.js stream handling and file-based session storage; Added tests for RSC HTML streaming, nonce injection, and cancellation handling; Added tests for SSR components, meta handling, and client version mismatch logic; Added tests for flat routes and manifest conversion; Added tests for react-router-dev internal utilities; Added tests for the React Router Architect adapter; Added tests for the Remix route config adapter; Added tests for turbo-stream v2 encode/decode round-trips; Added unit tests for the Express adapter; Expanded router history and data-strategy test coverage; Expanded test coverage for React Router DOM behaviors; New test utilities for React Router data router testing; Unstable Vite support for Node-based Remix apps.

Dependencies

React Router v8.4.0 release with Vite 7/8 and Node 22 support

This release updates the React Router monorepo to version 8.4.0, introducing support for Vite 7 and Vite 8 in the development tooling and integration templates. It also raises the minimum required Node.js version to 22.22.0 across all packages and integration helpers, ensuring compatibility with the latest runtime features and security standards.

(dependencies) · high confidence

Housekeeping

Added placeholder files for changelog generation in multiple packages

Empty .gitkeep files were added to the .changes directories of several React Router packages (create-react-router, react-router-architect, react-router-cloudflare, react-router-express, react-router-fs-routes, react-router-node, react-router-remix-routes-option-adapter, and react-router-serve). This establishes the directory structure required for automated changelog tools to track and generate release notes for these specific packages, supporting the new release process.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 36 → 49 (+13.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 56 → 44 (-12.8)
  • Architecture 87 (new)
  • Maturity 70 → 79 (+8.9)
  • Readiness 18 → 42 (+23.9)
  • Security 47 → 60 (+13.4)
  • Accessibility 77 (new)
  • Performance 60 (new)

Resolved (111)

  • (anonymous) (cognitive 19) (packages/react-router-dev/vite/static/refresh-utils.mjs)
  • ADR not followed: Do not clone request (decisions/0002-do-not-clone-request.md)
  • Boundary-crossing change coupling: vite.config.ts ↔ plugin.ts (integration/helpers/rsc-vite-framework/vite.config.ts)
  • Change coupling: hydrated-router.tsx ↔ global.ts (packages/react-router/lib/dom-export/hydrated-router.tsx)
  • Change coupling: plugin.ts ↔ virtual-route-modules.ts (packages/react-router-dev/vite/rsc/plugin.ts)
  • Change coupling: plugin.ts ↔ with-props.ts (packages/react-router-dev/vite/plugin.ts)
  • Change coupling: pr.ts ↔ github.ts (scripts/changes/pr.ts)
  • Change coupling: vite.config.ts ↔ vite.ts (integration/helpers/rsc-vite-framework/vite.config.ts)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 91 more

New (559)

  • (anonymous) (cognitive 20) (packages/react-router-dev/vite/static/refresh-utils.mjs)
  • Change coupling: build.ts ↔ plugin.ts (packages/react-router-dev/vite/build.ts)
  • Change coupling: data.ts ↔ server.ts (packages/react-router/lib/server-runtime/data.ts)
  • ClassTooLong: ShouldRevalidateFunctionArgs (packages/react-router/lib/router/utils.ts)
  • FileTooLong: config/config.ts (packages/react-router-dev/config/config.ts)
  • FileTooLong: create-react-router/index.ts (packages/create-react-router/index.ts)
  • FileTooLong: dom/lib.tsx (packages/react-router/lib/dom/lib.tsx)
  • FileTooLong: lib/components.tsx (packages/react-router/lib/components.tsx)
  • FileTooLong: lib/hooks.tsx (packages/react-router/lib/hooks.tsx)
  • FileTooLong: router/instrumentation.ts (packages/react-router/lib/router/instrumentation.ts)
  • FileTooLong: router/router.ts (packages/react-router/lib/router/router.ts)
  • FileTooLong: router/utils.ts (packages/react-router/lib/router/utils.ts)
  • FileTooLong: rsc/browser.tsx (packages/react-router/lib/rsc/browser.tsx)
  • FileTooLong: rsc/plugin.ts (packages/react-router-dev/vite/rsc/plugin.ts)
  • FileTooLong: rsc/server.rsc.ts (packages/react-router/lib/rsc/server.rsc.ts)
  • FileTooLong: server-runtime/server.ts (packages/react-router/lib/server-runtime/server.ts)
  • FileTooLong: ssr/components.tsx (packages/react-router/lib/dom/ssr/components.tsx)
  • FileTooLong: vite/plugin.ts (packages/react-router-dev/vite/plugin.ts)
  • FileTooLong: vite/route-chunks.ts (packages/react-router-dev/vite/route-chunks.ts)
  • FixmeComment (packages/react-router/lib/router/router.ts)
  • …and 539 more

Changes since last survey

  • 81 commits — 54 feature/other, 27 fixes

By area

  • packages/react-router — 28 commits
  • .github/workflows — 17 commits
  • (root) — 12 commits
  • docs/api — 7 commits
  • packages/react-router-dev — 4 commits
  • docs/how-to — 2 commits
  • packages/react-router-node — 2 commits
  • .github/skills — 1 commit
  • docs/explanation — 1 commit
  • docs/start — 1 commit
  • integration/error-sanitization-test.ts — 1 commit
  • integration/helpers — 1 commit
  • integration/manifest-reload-recovery-test.ts — 1 commit
  • packages/react-router-serve — 1 commit
  • scripts/changes — 1 commit
  • tutorials/address-book — 1 commit

Notable commits

  • fix: Fix HTML attribute escaping for RSC redirects (#15491)
  • fix: Fix address-book tutorial by upgrading Vite to v8 (#15473)
  • fix: Fix agentic pull request review failures (#15511)
  • fix: Fix agentic router context delivery (#15508)
  • fix: Fix change file
  • fix: Fix empty terminating splats with route-pattern matching (#15499)
  • fix: Fix integration test environment cleanup (#15471)
  • fix: Fix useRouterState documentation example (#15535)
  • fix: Revert "chore: trigger fresh bot-authored release PR"
  • fix: Revert "fix: normalize control characters in relative URLs (#15416)" (#15442)
  • fix: fix(dev): declare source maps from the route module transforms (#15440)
  • fix: fix(dev): use X-Forwarded-Proto for the dev request URL (#15466)
  • fix: fix(fog-of-war): don't cache aborted lazy route discoveries as discovered (#15399)
  • fix: fix(node): avoid retaining memory while racing stream reads (#15500)
  • fix: fix(react-router): re-enable manual scroll restoration after a bfcache restore (#15397)
  • fix: fix(react-router-serve): serve /.well-known files (#15340)
  • fix: fix(router): skip fetcher revalidation against a splat during lazy route discovery (#15395)
  • fix: fix: honor the relative option in useSubmit and fetcher.submit (#15400)
  • fix: fix: improve matching perf (#15417)
  • fix: fix: match optional static segments containing non-word characters (#15425)
  • …and 61 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

remix-run/react-router was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 291a913bf132aa0507fabf33bd8e82c4a71e5f12 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.