๐จ [security] [test] Update next 13.5.7 โ 15.4.0 (major) #179
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
๐จ Your current dependencies have known security vulnerabilities ๐จ
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
โณ๏ธ next (13.5.7 โ 15.4.0) ยท Repo
Security Advisories ๐จ
๐จ Information exposure in Next.js dev server due to lack of origin verification
๐จ Information exposure in Next.js dev server due to lack of origin verification
๐จ Next.js Race Condition to Cache Poisoning
๐จ Next.js Race Condition to Cache Poisoning
๐จ Next.js may leak x-middleware-subrequest-id to external hosts
๐จ Next.js may leak x-middleware-subrequest-id to external hosts
๐จ Next.js may leak x-middleware-subrequest-id to external hosts
๐จ Authorization Bypass in Next.js Middleware
๐จ Authorization Bypass in Next.js Middleware
๐จ Authorization Bypass in Next.js Middleware
๐จ Next.js Allows a Denial of Service (DoS) with Server Actions
๐จ Next.js Allows a Denial of Service (DoS) with Server Actions
๐จ Next.js Allows a Denial of Service (DoS) with Server Actions
๐จ Next.js authorization bypass vulnerability
๐จ Denial of Service condition in Next.js image optimization
๐จ Next.js Cache Poisoning
๐จ Next.js Server-Side Request Forgery in Server Actions
Release Notes
Too many releases to show here. View the full release notes.
Sorry, we couldn't find anything useful about this release.
โณ๏ธ @โplaywright/test (1.39.0 โ 1.53.0) ยท Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Sorry, we couldn't find anything useful about this release.
Sorry, we couldn't find anything useful about this release.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
fix: Move TypeScript to `devDependencies` (#848)
fix: Correct context for declaration files (#847)
fix: Use scoped JSX namespace (#846)
fix: bump peer dep for react 19 (#844)
chore: bump loader-utils version (#845)
chore: update issue template (#839)
fix: including global typing (#826)
Release Notes
2.8.1
2.8.0
2.7.0
2.6.3
2.6.2
2.6.1
2.6.0
2.5.3
2.5.2
2.5.1
2.5.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 71 commits:
2.8.1
Merge pull request #275 from microsoft/bug/es5-compat
Remove use of ES2015 syntax
Include non-enumerable keys in __importStar helper (#272)
Add missing registry-url parameter
Merge pull request #271 from microsoft/fix-publish
Fix publish workflow
2.8.0
Merge pull request #270 from microsoft/rewriteRelativeImportExtension
Missed update
Little optimizations
Add URL-ish test
Combine tsx case into regex
Test and fix invalid declaration-looking extensions
Do more with a regex
Shorten by one line
Case insensitivity, remove lookbehind
Add rewriteRelativeImportExtension helper
Merge pull request #269 from microsoft/test-infrastructure
Test export structure
Bump version to 2.7.0.
Use global 'Iterator.prototype' for downlevel generators (#267)
Implement deterministic collapse of 'await' in 'await using' (#262)
2.6.3
'await using' normative changes (#258)
Bump the github-actions group with 3 updates (#253)
Bump the github-actions group with 1 update (#242)
Bump the github-actions group with 1 update (#241)
Bump the github-actions group with 2 updates (#240)
JSDoc typo on `__exportStar`. (#221)
Bump the github-actions group with 1 update (#233)
Bump the github-actions group with 1 update (#230)
Bump the github-actions group with 2 updates (#228)
Pin CI actions missed in previous PR
CI: Hashpin sensitive actions and install dependabot (#226)
Fix __asyncGenerator to properly handle AsyncGeneratorUnwrapYieldResumption (#222)
Update codeql workflow using GUI (#223)
CI: set minimal permissions for GitHub Workflows (#218)
2.6.2
Merge pull request #217 from microsoft/bug/fix-modules-condition-types-path
Fix path to exports["module"]["types"]
2.6.1
Merge pull request #216 from microsoft/bug/205
Undo format on save
Stop using es6 syntax in the es6 file
Allow functions as values in __addDisposableResource (#215)
2.6.0
Add helpers for `using` and `await using` (#213)
2.5.3
Merge pull request #208 from microsoft/moar-modules
Do not reference tslib.es6.js from package.json exports
Bump version to 2.5.2.
Use named reexport to satsify incomplete TS symbol resolution (#204)
Reverse order of decorator-injected initializers (#202)
Merge pull request #200 from Andarist/fix/import-types
Update modules/index.d.ts
Merge pull request #201 from microsoft/fix-esm
Merge pull request #179 from guybedford/patch-4
Add default export to modules/index.js
Ensure tslib.es6.js is typed
Add Node-specific export condition for ESM entrypoint that re-exports CJS
Add propert declaration file for the `import` condition
Merge pull request #195 from xfq/https
http -> https
Merge pull request #194 from microsoft/bump-version-2.5
Bump package version to 2.5.0
Add support for __esDecorate and related helpers (#193)
Merge pull request #188 from microsoft/add-codeql
try paths: .
add codeql
Fix asyncDelegator reporting done too early (#187)
๐ @โemnapi/runtime (added, 1.4.3)
๐ @โimg/sharp-darwin-arm64 (added, 0.34.2)
๐ @โimg/sharp-darwin-x64 (added, 0.34.2)
๐ @โimg/sharp-libvips-darwin-arm64 (added, 1.1.0)
๐ @โimg/sharp-libvips-darwin-x64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-arm (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-arm64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-ppc64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-s390x (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-x64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linuxmusl-arm64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linuxmusl-x64 (added, 1.1.0)
๐ @โimg/sharp-linux-arm (added, 0.34.2)
๐ @โimg/sharp-linux-arm64 (added, 0.34.2)
๐ @โimg/sharp-linux-s390x (added, 0.34.2)
๐ @โimg/sharp-linux-x64 (added, 0.34.2)
๐ @โimg/sharp-linuxmusl-arm64 (added, 0.34.2)
๐ @โimg/sharp-linuxmusl-x64 (added, 0.34.2)
๐ @โimg/sharp-wasm32 (added, 0.34.2)
๐ @โimg/sharp-win32-arm64 (added, 0.34.2)
๐ @โimg/sharp-win32-ia32 (added, 0.34.2)
๐ @โimg/sharp-win32-x64 (added, 0.34.2)
๐ color (added, 4.2.3)
๐ color-string (added, 1.9.1)
๐ detect-libc (added, 2.0.4)
๐ is-arrayish (added, 0.3.2)
๐ sharp (added, 0.34.2)
๐ simple-swizzle (added, 0.2.2)
๐๏ธ @โnext/swc-win32-ia32-msvc (removed)
๐๏ธ busboy (removed)
๐๏ธ glob-to-regexp (removed)
๐๏ธ streamsearch (removed)
๐๏ธ watchpack (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands