Skip to content

Update Next.js versions in starters to fix React2Shell vulnerability#566

Merged
Yuangwang merged 1 commit intomainfrom
fix-react2shell
Apr 30, 2026
Merged

Update Next.js versions in starters to fix React2Shell vulnerability#566
Yuangwang merged 1 commit intomainfrom
fix-react2shell

Conversation

@Yuangwang
Copy link
Copy Markdown
Collaborator

No description provided.

Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the 'next' dependency in two starter projects. While the firebase-ecommerce starter is updated to version 15.1.9, the shopify-ecommerce starter is only updated to 15.0.5. Feedback indicates that version 15.0.5 remains vulnerable to CVE-2025-24357 and should be upgraded to 15.1.9 to ensure security and consistency across the repository.

Comment thread starters/nextjs/shopify-ecommerce/package.json
@Yuangwang Yuangwang merged commit 9978429 into main Apr 30, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants