Skip to content

[Snyk] Security upgrade next from 15.5.18 to 16.1.7#582

Merged
Dargon789 merged 4 commits into
0xsequence-sdkfrom
snyk-fix-acc3a6bcee7e9180369d6ee5023ee21f
May 24, 2026
Merged

[Snyk] Security upgrade next from 15.5.18 to 16.1.7#582
Dargon789 merged 4 commits into
0xsequence-sdkfrom
snyk-fix-acc3a6bcee7e9180369d6ee5023ee21f

Conversation

@Dargon789
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the pnpm dependencies of this project.

Snyk changed the following file(s):

  • extras/web/package.json
⚠️ Warning
Failed to update the pnpm-lock.yaml, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-NEXT-15105315
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-NEXT-15674556

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

@codesandbox
Copy link
Copy Markdown

codesandbox Bot commented May 22, 2026

Review or Edit in CodeSandbox

Open the branch in Web EditorVS CodeInsiders

Open Preview

@bolt-new-by-stackblitz
Copy link
Copy Markdown

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@vercel
Copy link
Copy Markdown

vercel Bot commented May 22, 2026

Deployment failed with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/dargon789-forge?upgradeToPro=build-rate-limit

@vercel
Copy link
Copy Markdown

vercel Bot commented May 22, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
sequence-js-docs Ready Ready Preview, Comment May 22, 2026 6:33am
sequence-js-web Ready Ready Preview, Comment May 22, 2026 6:33am
sequence.js Ready Ready Preview, Comment May 22, 2026 6:33am
wagmi-project Ready Ready Preview, Comment May 22, 2026 6:33am

@snyk-io
Copy link
Copy Markdown

snyk-io Bot commented May 22, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the next dependency in extras/web/package.json from version 15.5.16 to 16.1.7. The reviewer identified a critical omission where the pnpm-lock.yaml file was not updated, which is necessary for deterministic builds and CI stability. Additionally, there is a discrepancy between the version mentioned in the pull request title and the version being replaced in the code.

Comment thread extras/web/package.json
Comment thread extras/web/package.json
@Dargon789 Dargon789 merged commit 523ac27 into 0xsequence-sdk May 24, 2026
19 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants