Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade next from 14.2.5 to 14.2.10 #15

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

ShubhamTiwari909
Copy link
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 649/1000
Why? Has a fix available, CVSS 8.7
Acceptance of Extraneous Untrusted Data With Trusted Data
SNYK-JS-NEXT-8025427
No No Known Exploit
high severity /1000
Why?
Uncontrolled Recursion
SNYK-JS-NEXT-8186172
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: next The new version differs by 102 commits.
  • 937651f v14.2.10
  • 7ed7f12 Remove invalid fallback revalidate value (#69990)
  • 99de057 Revert server action optimization (#69925)
  • 24647b9 Add ability to customize Cache-Control (#69802)
  • 6fa8982 v14.2.9
  • 7998745 test: lock ts type check (#69889)
  • 4bd3849 create-next-app: fix font file corruption when using import alias (#69806)
  • 3756801 test: check most possible combination of CNA flags
  • 9a72ad6 unpin CNA tests from 14.2.3
  • 747d365 Fix metadata prop merging (#69807)
  • 196dab6 Fix status code for /_not-found route (#64058) (#69808)
  • e50ad14 Fix middleware fallback: false case (#69799)
  • bf48448 Disable experimental.optimizeServer by default (#69788)
  • 86547db test: both wrapped and unwrapped dynamic() (#69780)
  • a882e6e Revert "Fix esm property def in flight loader (#66990)" (#69749)
  • 63b999c v14.2.8
  • 55e4ef2 Allow external image urls with _next/image pathname to be rendered via Image component (#69586)
  • d09b769 feat(turbopack): add support for esm externals in app dir (#64918)
  • dafdc81 test: convert app-external.test.ts to nextTestSetup
  • 2c80812 Turbopack: Allow client components from foreign code in app routes (#64751)
  • 6473113 Improve SWC transform ID generation (#69183)
  • 9c4efb9 Apply optimization for unused actions (#69178)
  • 5eff016 refactor: create shared utils for mod resource (#69145)
  • c8bde3e optimize server actions (#66523)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Copy link

vercel bot commented Oct 18, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
blog-dev-js ✅ Ready (Inspect) Visit Preview 💬 Add feedback Oct 18, 2024 8:32am
blog-dev-js-vvop ✅ Ready (Inspect) Visit Preview 💬 Add feedback Oct 18, 2024 8:32am

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants