[Snyk] Security upgrade next from 15.5.18 to 16.1.7#582
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-NEXT-15105315 - https://snyk.io/vuln/SNYK-JS-NEXT-15674556
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-NEXT-15105315 - https://snyk.io/vuln/SNYK-JS-NEXT-15674556
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
|
|
|
Deployment failed with the following error: Learn More: https://vercel.com/dargon789-forge?upgradeToPro=build-rate-limit |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
There was a problem hiding this comment.
Code Review
This pull request updates the next dependency in extras/web/package.json from version 15.5.16 to 16.1.7. The reviewer identified a critical omission where the pnpm-lock.yaml file was not updated, which is necessary for deterministic builds and CI stability. Additionally, there is a discrepancy between the version mentioned in the pull request title and the version being replaced in the code.
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-NEXT-15105315 - https://snyk.io/vuln/SNYK-JS-NEXT-15674556
Snyk has created this PR to fix 2 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
extras/web/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-NEXT-15105315
SNYK-JS-NEXT-15674556
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling