Skip to content

Daily security sweep — backlog #17

Description

@benfrank241

Running log from the daily security sweep of items that could not be shipped as part of a bundle, or that block verification. Newest entries appended at the bottom.


2026-08-26 — npm run build / npm run lint fails on main (pre-existing, blocks bundle verification)

Not caused by a dependency bump. Recorded here because it makes npm run build exit non-zero for every PR, so the sweep cannot use a green build as its signal in this repo.

Exact signature:

Failed to compile.

./src/app/api/createSourceConnector/route.ts
116:19  Error: Unexpected any. Specify a different type.  @typescript-eslint/no-explicit-any

./src/app/api/manage-oauth-user/[connectorId]/route.ts
16:34  Error: Unexpected any. Specify a different type.  @typescript-eslint/no-explicit-any

Plus 4 non-fatal @typescript-eslint/no-unused-vars warnings in src/app/api/getVectorizeConfig/route.ts:9, src/app/api/googleDrive/getGoogleOAuthConfig/route.ts:8, src/app/dropbox/page.tsx:44, src/app/googleDrive/page.tsx:44.

TypeScript itself is clean (npx tsc --noEmit exits 0), and the Next.js compile step succeeds — it is only the ESLint gate that fails.

Suggested fix: type the two any values, or add targeted // eslint-disable-next-line @typescript-eslint/no-explicit-any comments. Two-line change.

Also noted: next lint prints `next lint` is deprecated and will be removed in Next.js 16 — this repo will need the ESLint CLI migration (npx @next/codemod@canary next-lint-to-eslint-cli .) before any Next 16 upgrade.


2026-08-26 — PR #14 is stale and should be closed

Not a verification failure, but it needs a human decision.

#14 ("upgrade Next.js to 15.5.9 to patch CVE-2025-55184 and CVE-2025-55183", opened 2025-12-12) moves next from ^15.5.7 → ^15.5.9. main has been on ^15.5.18 since #15 landed, so #14 is now a downgrade and GitHub already reports it as CONFLICTING / DIRTY. Neither CVE-2025-55184 nor CVE-2025-55183 appears in the current open-alert set, and 15.5.9 cannot close any of the 8 open next alerts, which all require ≥ 15.5.21.

Recommend closing #14 as superseded by #16, which takes next to 15.5.24.


2026-08-26 — no other backlog items

All 20 open Dependabot alerts were bundled into #16 and verified. Nothing was dismissed, and nothing had to be dropped for a conflict or an ERESOLVE.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions