Skip to content

fix(react-store): preserve RSC client boundaries - #391

Merged
schiller-manuel merged 2 commits into
alphafrom
codex/fix-react-store-rsc-boundaries
Oct 10, 2026
Merged

schiller-manuel merged 2 commits into
alphafrom
codex/fix-react-store-rsc-boundaries

Conversation

@schiller-manuel

Copy link
Copy Markdown
Contributor

🎯 Changes

React Store's alpha selector imports useRef and useSyncExternalStore directly from React. In an RSC graph these resolve to React's react-server entry, which does not export them. This breaks the production Rsbuild RSC build in TanStack Router #8657.

Mark all seven React hook/context modules with 'use client', preserving the boundary in both published ESM and CJS output. Keep the mixed package barrel unmarked so its core createAtom, createStore, and batch reexports remain callable in Server Components. Ordinary SSR continues to execute the existing hooks and server snapshots.

Validation:

  • Public package imports through React's real ESM/CJS RSC loaders: core APIs work, and calling each React API produces the client-boundary error. Both cases fail before the fix and pass afterward.
  • Ordinary renderToString exercises every React API family, returns the expected values, and creates no subscriptions.
  • pnpm test:pr --base=origin/alpha: all 108 tasks pass, including runtime, TypeScript matrix, lint, package builds, and examples.
  • Final packed dependency: all 50 Router/Start validation tasks pass, including unit, types, lint, package builds, both Vite/Rsbuild production RSC builds, and the complete Rsbuild RSC browser suite (258 passed, one skipped).
  • Full 18-scenario bundle comparison: raw sizes and chunk counts are unchanged; gzip is unchanged in 17 scenarios and increases by one byte in the Rsbuild IIFE scenario. The actual Vite RSC client assets are byte-identical. The Rsbuild RSC manifest contains only the reachable selector leaf, with no additional async chunk.

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested code changes locally with pnpm test:pr, or these tests do not apply to this pull request.
  • I fully understand the code in this pull request, including any code generated with AI assistance.

🚀 Release Impact

  • This change affects published code, and I have generated a changeset.
  • This change is docs/CI/dev-only (no release).

The patch changeset is verified with Changesets 3 to produce @tanstack/react-store@1.0.0-alpha.1 on the alpha branch.

@changeset-bot

changeset-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 114dedf

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@tanstack/react-store Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: TanStack/store/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 76f8f06d-1168-4e3b-be24-740732edaa12

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-10T12:22:11.031351Z 114dedf PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@nx-cloud

nx-cloud Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit 114dedf

Command Status Duration Result
nx affected --targets=test:sherif,test:knip,tes... ✅ Succeeded 2m View ↗
nx run-many --target=build --exclude=examples/** ✅ Succeeded 8s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-10 12:22:11 UTC

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedreact-server-dom-webpack@​19.2.5100797850100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
High CVE: react-server-dom: Denial of Service in Server Functions in npm react-server-dom-webpack

CVE: GHSA-wx67-qw84-cm4g react-server-dom: Denial of Service in Server Functions (HIGH)

Affected versions: >= 19.0.0 < 19.0.8; >= 19.1.0 < 19.1.9; >= 19.2.0 < 19.2.8

Patched version: 19.2.8

From: packages/react-store/package.json → npm/react-server-dom-webpack@19.2.5

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/react-server-dom-webpack@19.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
High CVE: Facebook React has a Denial of Service Vulnerability in React Server Components in npm react-server-dom-webpack

CVE: GHSA-rv78-f8rc-xrxh Facebook React has a Denial of Service Vulnerability in React Server Components (HIGH)

Affected versions: >= 19.0.0 < 19.0.6; >= 19.1.0 < 19.1.7; >= 19.2.0 < 19.2.6

Patched version: 19.2.6

From: packages/react-store/package.json → npm/react-server-dom-webpack@19.2.5

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/react-server-dom-webpack@19.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Deprecated by its maintainer: npm react-server-dom-webpack

Reason: High Security Vulnerability in React Server Components

From: packages/react-store/package.json → npm/react-server-dom-webpack@19.2.5

ℹ Read more on: This package | This alert | What is a deprecated package?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/react-server-dom-webpack@19.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@pkg-pr-new

pkg-pr-new Bot commented Oct 10, 2026

Copy link
Copy Markdown
@tanstack/angular-store

npm i https://pkg.pr.new/@tanstack/angular-store@391

@tanstack/lit-store

npm i https://pkg.pr.new/@tanstack/lit-store@391

@tanstack/octane-store

npm i https://pkg.pr.new/@tanstack/octane-store@391

@tanstack/preact-store

npm i https://pkg.pr.new/@tanstack/preact-store@391

@tanstack/react-store

npm i https://pkg.pr.new/@tanstack/react-store@391

@tanstack/solid-store

npm i https://pkg.pr.new/@tanstack/solid-store@391

@tanstack/store

npm i https://pkg.pr.new/@tanstack/store@391

@tanstack/svelte-store

npm i https://pkg.pr.new/@tanstack/svelte-store@391

@tanstack/vue-store

npm i https://pkg.pr.new/@tanstack/vue-store@391

commit: 114dedf

@schiller-manuel
schiller-manuel merged commit 9559024 into alpha Oct 10, 2026
8 of 9 checks passed
@schiller-manuel
schiller-manuel deleted the codex/fix-react-store-rsc-boundaries branch October 10, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants