Running log from the daily security sweep of items that could not be shipped as part of a bundle, or that block verification. Newest entries appended at the bottom.
2026-08-26 — npm run build / npm run lint fails on main (pre-existing, blocks bundle verification)
Not caused by a dependency bump. Recorded here because it makes npm run build exit non-zero for every PR, so the sweep cannot use a green build as its signal in this repo.
Exact signature:
Failed to compile.
./src/app/api/createSourceConnector/route.ts
116:19 Error: Unexpected any. Specify a different type. @typescript-eslint/no-explicit-any
./src/app/api/manage-oauth-user/[connectorId]/route.ts
16:34 Error: Unexpected any. Specify a different type. @typescript-eslint/no-explicit-any
Plus 4 non-fatal @typescript-eslint/no-unused-vars warnings in src/app/api/getVectorizeConfig/route.ts:9, src/app/api/googleDrive/getGoogleOAuthConfig/route.ts:8, src/app/dropbox/page.tsx:44, src/app/googleDrive/page.tsx:44.
TypeScript itself is clean (npx tsc --noEmit exits 0), and the Next.js compile step succeeds — it is only the ESLint gate that fails.
Suggested fix: type the two any values, or add targeted // eslint-disable-next-line @typescript-eslint/no-explicit-any comments. Two-line change.
Also noted: next lint prints `next lint` is deprecated and will be removed in Next.js 16 — this repo will need the ESLint CLI migration (npx @next/codemod@canary next-lint-to-eslint-cli .) before any Next 16 upgrade.
2026-08-26 — PR #14 is stale and should be closed
Not a verification failure, but it needs a human decision.
#14 ("upgrade Next.js to 15.5.9 to patch CVE-2025-55184 and CVE-2025-55183", opened 2025-12-12) moves next from ^15.5.7 → ^15.5.9. main has been on ^15.5.18 since #15 landed, so #14 is now a downgrade and GitHub already reports it as CONFLICTING / DIRTY. Neither CVE-2025-55184 nor CVE-2025-55183 appears in the current open-alert set, and 15.5.9 cannot close any of the 8 open next alerts, which all require ≥ 15.5.21.
Recommend closing #14 as superseded by #16, which takes next to 15.5.24.
2026-08-26 — no other backlog items
All 20 open Dependabot alerts were bundled into #16 and verified. Nothing was dismissed, and nothing had to be dropped for a conflict or an ERESOLVE.
Running log from the daily security sweep of items that could not be shipped as part of a bundle, or that block verification. Newest entries appended at the bottom.
2026-08-26 —
npm run build/npm run lintfails onmain(pre-existing, blocks bundle verification)Not caused by a dependency bump. Recorded here because it makes
npm run buildexit non-zero for every PR, so the sweep cannot use a green build as its signal in this repo.vectorize-io/test-vectorize-connect-sdknpm run build(next buildruns ESLint before emitting) andnpm run lintmain@ffc649b, and identically on the sweep branchchore/security-daily-20260826-test-vectorize-connect-sdk-npm-root— byte-identical output on both, so the bundle in chore(security): daily sweep 2026-08-26 — bundle 20 Dependabot fixes (npm, root package-lock.json) #16 introduces no lint delta.Exact signature:
Plus 4 non-fatal
@typescript-eslint/no-unused-varswarnings insrc/app/api/getVectorizeConfig/route.ts:9,src/app/api/googleDrive/getGoogleOAuthConfig/route.ts:8,src/app/dropbox/page.tsx:44,src/app/googleDrive/page.tsx:44.TypeScript itself is clean (
npx tsc --noEmitexits 0), and the Next.js compile step succeeds — it is only the ESLint gate that fails.Suggested fix: type the two
anyvalues, or add targeted// eslint-disable-next-line @typescript-eslint/no-explicit-anycomments. Two-line change.Also noted:
next lintprints`next lint` is deprecated and will be removed in Next.js 16— this repo will need the ESLint CLI migration (npx @next/codemod@canary next-lint-to-eslint-cli .) before any Next 16 upgrade.2026-08-26 — PR #14 is stale and should be closed
Not a verification failure, but it needs a human decision.
#14 ("upgrade Next.js to 15.5.9 to patch CVE-2025-55184 and CVE-2025-55183", opened 2025-12-12) moves
nextfrom^15.5.7→^15.5.9.mainhas been on^15.5.18since #15 landed, so #14 is now a downgrade and GitHub already reports it asCONFLICTING/DIRTY. Neither CVE-2025-55184 nor CVE-2025-55183 appears in the current open-alert set, and 15.5.9 cannot close any of the 8 opennextalerts, which all require ≥ 15.5.21.Recommend closing #14 as superseded by #16, which takes
nextto 15.5.24.2026-08-26 — no other backlog items
All 20 open Dependabot alerts were bundled into #16 and verified. Nothing was dismissed, and nothing had to be dropped for a conflict or an
ERESOLVE.