Skip to content

test(deps): Bump Next.js in E2E test apps to fix Server Components DoS#20633

Merged
chargome merged 1 commit intodevelopfrom
fix/dependabot-alert-next-dos
May 4, 2026
Merged

test(deps): Bump Next.js in E2E test apps to fix Server Components DoS#20633
chargome merged 1 commit intodevelopfrom
fix/dependabot-alert-next-dos

Conversation

@chargome
Copy link
Copy Markdown
Member

@chargome chargome commented May 4, 2026

Summary

  • Bumps next 15.5.14 → 15.5.15 in nextjs-15, nextjs-15-intl
  • Bumps next 16.1.7 → 16.2.3 in nextjs-16, nextjs-16-cacheComponents, nextjs-16-trailing-slash, nextjs-16-bun, nextjs-16-tunnel, nextjs-sourcemaps
  • Fixes high-severity DoS vulnerability in Next.js Server Components

Bumps next 15.5.14 → 15.5.15 and next 16.1.7 → 16.2.3 across 8 E2E
test applications to fix a high-severity DoS vulnerability in Server
Components.

Fixes Dependabot alerts #1394, #1388, #1387, #1383, #1382, #1381,
#1380, #1379, #1378.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@chargome chargome changed the title fix(deps): Bump Next.js in E2E test apps to fix Server Components DoS test(deps): Bump Next.js in E2E test apps to fix Server Components DoS May 4, 2026
@chargome chargome self-assigned this May 4, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 4, 2026

size-limit report 📦

Path Size % Change Change
@sentry/browser 26.31 kB - -
@sentry/browser - with treeshaking flags 24.8 kB - -
@sentry/browser (incl. Tracing) 44.19 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 46.41 kB - -
@sentry/browser (incl. Tracing, Profiling) 49.16 kB - -
@sentry/browser (incl. Tracing, Replay) 83.57 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 73.04 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 88.25 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 100.86 kB - -
@sentry/browser (incl. Feedback) 43.46 kB - -
@sentry/browser (incl. sendFeedback) 31.12 kB - -
@sentry/browser (incl. FeedbackAsync) 36.2 kB - -
@sentry/browser (incl. Metrics) 27.62 kB - -
@sentry/browser (incl. Logs) 27.74 kB - -
@sentry/browser (incl. Metrics & Logs) 28.44 kB - -
@sentry/react 28.05 kB - -
@sentry/react (incl. Tracing) 46.42 kB - -
@sentry/vue 31.18 kB - -
@sentry/vue (incl. Tracing) 46.03 kB - -
@sentry/svelte 26.33 kB - -
CDN Bundle 28.91 kB - -
CDN Bundle (incl. Tracing) 46.95 kB - -
CDN Bundle (incl. Logs, Metrics) 30.34 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 48.06 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 69.4 kB - -
CDN Bundle (incl. Tracing, Replay) 84.1 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.16 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 89.9 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 91.01 kB - -
CDN Bundle - uncompressed 84.71 kB - -
CDN Bundle (incl. Tracing) - uncompressed 140.29 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 88.9 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 143.75 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 212.85 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 258.1 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 261.54 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 271.79 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 275.23 kB - -
@sentry/nextjs (client) 48.92 kB - -
@sentry/sveltekit (client) 44.67 kB - -
@sentry/node-core 59.13 kB +0.02% +11 B 🔺
@sentry/node 170.42 kB +0.01% +12 B 🔺
@sentry/node - without tracing 97 kB +0.02% +10 B 🔺
@sentry/aws-serverless 113.85 kB +0.03% +32 B 🔺
@sentry/cloudflare (withSentry) - minified 165.08 kB - -
@sentry/cloudflare (withSentry) 417.39 kB - -

View base workflow run

@chargome chargome merged commit 9ac7d0b into develop May 4, 2026
56 checks passed
@chargome chargome deleted the fix/dependabot-alert-next-dos branch May 4, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants