๐จ [security] [test] Update next 13.5.7 โ 15.4.0 (major) #179
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
๐จ Your current dependencies have known security vulnerabilities ๐จ
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
โณ๏ธ next (13.5.7 โ 15.4.0) ยท Repo
Security Advisories ๐จ
๐จ Information exposure in Next.js dev server due to lack of origin verification
๐จ Information exposure in Next.js dev server due to lack of origin verification
๐จ Next.js Race Condition to Cache Poisoning
๐จ Next.js Race Condition to Cache Poisoning
๐จ Next.js may leak x-middleware-subrequest-id to external hosts
๐จ Next.js may leak x-middleware-subrequest-id to external hosts
๐จ Next.js may leak x-middleware-subrequest-id to external hosts
๐จ Authorization Bypass in Next.js Middleware
๐จ Authorization Bypass in Next.js Middleware
๐จ Authorization Bypass in Next.js Middleware
๐จ Next.js Allows a Denial of Service (DoS) with Server Actions
๐จ Next.js Allows a Denial of Service (DoS) with Server Actions
๐จ Next.js Allows a Denial of Service (DoS) with Server Actions
๐จ Next.js authorization bypass vulnerability
๐จ Denial of Service condition in Next.js image optimization
๐จ Next.js Cache Poisoning
๐จ Next.js Server-Side Request Forgery in Server Actions
Release Notes
Too many releases to show here. View the full release notes.
Sorry, we couldn't find anything useful about this release.
โณ๏ธ @โplaywright/test (1.39.0 โ 1.53.0) ยท Repo
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Sorry, we couldn't find anything useful about this release.
Sorry, we couldn't find anything useful about this release.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
fix: Move TypeScript to `devDependencies` (#848)fix: Correct context for declaration files (#847)fix: Use scoped JSX namespace (#846)fix: bump peer dep for react 19 (#844)chore: bump loader-utils version (#845)chore: update issue template (#839)fix: including global typing (#826)Release Notes
2.8.1
2.8.0
2.7.0
2.6.3
2.6.2
2.6.1
2.6.0
2.5.3
2.5.2
2.5.1
2.5.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 71 commits:
2.8.1Merge pull request #275 from microsoft/bug/es5-compatRemove use of ES2015 syntaxInclude non-enumerable keys in __importStar helper (#272)Add missing registry-url parameterMerge pull request #271 from microsoft/fix-publishFix publish workflow2.8.0Merge pull request #270 from microsoft/rewriteRelativeImportExtensionMissed updateLittle optimizationsAdd URL-ish testCombine tsx case into regexTest and fix invalid declaration-looking extensionsDo more with a regexShorten by one lineCase insensitivity, remove lookbehindAdd rewriteRelativeImportExtension helperMerge pull request #269 from microsoft/test-infrastructureTest export structureBump version to 2.7.0.Use global 'Iterator.prototype' for downlevel generators (#267)Implement deterministic collapse of 'await' in 'await using' (#262)2.6.3'await using' normative changes (#258)Bump the github-actions group with 3 updates (#253)Bump the github-actions group with 1 update (#242)Bump the github-actions group with 1 update (#241)Bump the github-actions group with 2 updates (#240)JSDoc typo on `__exportStar`. (#221)Bump the github-actions group with 1 update (#233)Bump the github-actions group with 1 update (#230)Bump the github-actions group with 2 updates (#228)Pin CI actions missed in previous PRCI: Hashpin sensitive actions and install dependabot (#226)Fix __asyncGenerator to properly handle AsyncGeneratorUnwrapYieldResumption (#222)Update codeql workflow using GUI (#223)CI: set minimal permissions for GitHub Workflows (#218)2.6.2Merge pull request #217 from microsoft/bug/fix-modules-condition-types-pathFix path to exports["module"]["types"]2.6.1Merge pull request #216 from microsoft/bug/205Undo format on saveStop using es6 syntax in the es6 fileAllow functions as values in __addDisposableResource (#215)2.6.0Add helpers for `using` and `await using` (#213)2.5.3Merge pull request #208 from microsoft/moar-modulesDo not reference tslib.es6.js from package.json exportsBump version to 2.5.2.Use named reexport to satsify incomplete TS symbol resolution (#204)Reverse order of decorator-injected initializers (#202)Merge pull request #200 from Andarist/fix/import-typesUpdate modules/index.d.tsMerge pull request #201 from microsoft/fix-esmMerge pull request #179 from guybedford/patch-4Add default export to modules/index.jsEnsure tslib.es6.js is typedAdd Node-specific export condition for ESM entrypoint that re-exports CJSAdd propert declaration file for the `import` conditionMerge pull request #195 from xfq/httpshttp -> httpsMerge pull request #194 from microsoft/bump-version-2.5Bump package version to 2.5.0Add support for __esDecorate and related helpers (#193)Merge pull request #188 from microsoft/add-codeqltry paths: .add codeqlFix asyncDelegator reporting done too early (#187)๐ @โemnapi/runtime (added, 1.4.3)
๐ @โimg/sharp-darwin-arm64 (added, 0.34.2)
๐ @โimg/sharp-darwin-x64 (added, 0.34.2)
๐ @โimg/sharp-libvips-darwin-arm64 (added, 1.1.0)
๐ @โimg/sharp-libvips-darwin-x64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-arm (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-arm64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-ppc64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-s390x (added, 1.1.0)
๐ @โimg/sharp-libvips-linux-x64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linuxmusl-arm64 (added, 1.1.0)
๐ @โimg/sharp-libvips-linuxmusl-x64 (added, 1.1.0)
๐ @โimg/sharp-linux-arm (added, 0.34.2)
๐ @โimg/sharp-linux-arm64 (added, 0.34.2)
๐ @โimg/sharp-linux-s390x (added, 0.34.2)
๐ @โimg/sharp-linux-x64 (added, 0.34.2)
๐ @โimg/sharp-linuxmusl-arm64 (added, 0.34.2)
๐ @โimg/sharp-linuxmusl-x64 (added, 0.34.2)
๐ @โimg/sharp-wasm32 (added, 0.34.2)
๐ @โimg/sharp-win32-arm64 (added, 0.34.2)
๐ @โimg/sharp-win32-ia32 (added, 0.34.2)
๐ @โimg/sharp-win32-x64 (added, 0.34.2)
๐ color (added, 4.2.3)
๐ color-string (added, 1.9.1)
๐ detect-libc (added, 2.0.4)
๐ is-arrayish (added, 0.3.2)
๐ sharp (added, 0.34.2)
๐ simple-swizzle (added, 0.2.2)
๐๏ธ @โnext/swc-win32-ia32-msvc (removed)
๐๏ธ busboy (removed)
๐๏ธ glob-to-regexp (removed)
๐๏ธ streamsearch (removed)
๐๏ธ watchpack (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands