Skip to content

chore(deps): bump next to 16.2.3 + transitive CVE fixes#2

Merged
t4sh merged 1 commit into
mainfrom
chore/deps-next-16.2.3
Apr 18, 2026
Merged

chore(deps): bump next to 16.2.3 + transitive CVE fixes#2
t4sh merged 1 commit into
mainfrom
chore/deps-next-16.2.3

Conversation

@t4sh
Copy link
Copy Markdown
Contributor

@t4sh t4sh commented Apr 18, 2026

Clears 14 Dependabot alerts.

Direct bumps:

  • next: 16.1.416.2.3 — resolves 8 alerts (Server Components DoS, HTTP smuggling via rewrites, null-origin CSRF bypass, image-optimizer DoS, PPR resume buffering, remotePatterns DoS, HMR CSRF, and one DoS via deserialization).
  • eslint-config-next pinned to 16.2.3 for alignment.

Transitive overrides (all dev-only paths — eslint toolchain):

Verified: npm audit = 0 vulnerabilities. next build passes.

Part of the github-hygiene sweep (post security + license hardening).

@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 18, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
erpai-cli-releases Ready Ready Preview, Comment Apr 18, 2026 3:01pm

Clears 14 Dependabot alerts:
- next 16.1.4 → 16.2.3 (8 alerts: Server Components DoS, HTTP smuggling
  via rewrites, null-origin CSRF bypass, image-optimizer DoS, etc.)
- eslint-config-next pinned to match
- overrides: flatted ^3.4.2 (GHSA-rf6f-7fwh-wjgh), minimatch ^9.0.7
  (GHSA-7r86-cg39-jmmj), picomatch ^4.0.4 (GHSA-3v7f-55p6-f55p),
  ajv ^6.14.0 (GHSA-2g4f-4pwh-qvx6)

All transitive fixes scoped to dev-only paths (eslint toolchain).
npm audit clean. next build passes.

Part of the github-hygiene sweep (post security + license hardening).
@t4sh t4sh force-pushed the chore/deps-next-16.2.3 branch from c3eda94 to 5ca3800 Compare April 18, 2026 15:01
@t4sh t4sh merged commit 01c1578 into main Apr 18, 2026
5 of 6 checks passed
@t4sh t4sh deleted the chore/deps-next-16.2.3 branch April 18, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant