fix(deps): patch Next.js and dependency security advisories - #651
Draft
aryamthecodebreaker wants to merge 1 commit into
Draft
fix(deps): patch Next.js and dependency security advisories#651aryamthecodebreaker wants to merge 1 commit into
aryamthecodebreaker wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The current audit reports critical Next.js and high-severity sharp/js-yaml advisories, plus moderate Hono and Vitest mocker advisories. Update Next.js and its ESLint configuration to 16.3.4, sharp to 0.35.4, js-yaml to 4.3.2, Vitest to 4.1.11, and the Hono dependency to 4.13.7. Keep React 19.2.7 and the Vitest 4 major line.
The root overrides are updated along with the lockfile so later installs cannot restore the vulnerable pinned versions. Native packages for all supported platforms remain in the lockfile.
Validation in progress: the updated lockfile reports zero vulnerabilities. Clean installation, full CI, cross-platform compatibility, and browser verification must pass before merge. This PR contains dependency repairs only; it does not publish a FixMap version or merge the v0.10 draft.