Skip to content

fix(deps): patch Next.js and dependency security advisories - #651

Draft
aryamthecodebreaker wants to merge 1 commit into
mainfrom
codex/security-september-9
Draft

fix(deps): patch Next.js and dependency security advisories#651
aryamthecodebreaker wants to merge 1 commit into
mainfrom
codex/security-september-9

Conversation

@aryamthecodebreaker

Copy link
Copy Markdown
Owner

The current audit reports critical Next.js and high-severity sharp/js-yaml advisories, plus moderate Hono and Vitest mocker advisories. Update Next.js and its ESLint configuration to 16.3.4, sharp to 0.35.4, js-yaml to 4.3.2, Vitest to 4.1.11, and the Hono dependency to 4.13.7. Keep React 19.2.7 and the Vitest 4 major line.

The root overrides are updated along with the lockfile so later installs cannot restore the vulnerable pinned versions. Native packages for all supported platforms remain in the lockfile.

Validation in progress: the updated lockfile reports zero vulnerabilities. Clean installation, full CI, cross-platform compatibility, and browser verification must pass before merge. This PR contains dependency repairs only; it does not publish a FixMap version or merge the v0.10 draft.

@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
fixmap Ready Ready Preview Sep 9, 2026 2:13pm UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant