Skip to content

[Chore] Update Next.js security fixes#713

Merged
mrubens merged 1 commit into
developfrom
fix/nextjs-security-0r3wfy5kmpoyu
Jul 23, 2026
Merged

[Chore] Update Next.js security fixes#713
mrubens merged 1 commit into
developfrom
fix/nextjs-security-0r3wfy5kmpoyu

Conversation

@roomote-roomote

Copy link
Copy Markdown
Contributor

Created by Roomote. Follow up by mentioning @roomote-roomote or in the web UI.

What changed

  • Updated the web application's direct Next.js runtime dependency from 16.2.6 to 16.2.11.
  • Refreshed the pnpm resolution, including the matching Next.js runtime binaries and peer dependency references.

Why this change was made

Next.js versions before 16.2.11 are affected by the related Dependabot runtime security alerts #49 through #57. This update adopts the first patched release for that alert bundle.

Impact

The web application resolves Next.js 16.2.11, removing the vulnerable 16.2.6 resolution. The web build, repository linting, and repository type checks pass; the full web test suite has six environment-dependent failures (database/S3 timeouts and configured app URL expectations) that are unrelated to this dependency-only change.

@roomote-roomote

roomote-roomote Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

No code issues found. See task

Reviewed 271c941

@mrubens
mrubens marked this pull request as ready for review July 23, 2026 11:08
@mrubens
mrubens merged commit 7692120 into develop Jul 23, 2026
17 checks passed
@mrubens
mrubens deleted the fix/nextjs-security-0r3wfy5kmpoyu branch July 23, 2026 11:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants