-
Notifications
You must be signed in to change notification settings - Fork 327
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(nextjs): Update dependency next to v14.2.25 [SECURITY] #5418
Conversation
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
|
bfe9216
to
c8a08d8
Compare
c8a08d8
to
27d9c45
Compare
27d9c45
to
10438cf
Compare
10438cf
to
2488d7e
Compare
2488d7e
to
a593f74
Compare
a593f74
to
1519a93
Compare
1519a93
to
c3461e3
Compare
Pull request was closed
c3461e3
to
57d0b34
Compare
57d0b34
to
5a41f3b
Compare
c534de9
to
d18c5bc
Compare
d18c5bc
to
fe9f5fb
Compare
fe9f5fb
to
b1e805c
Compare
b1e805c
to
a5a4ac0
Compare
a5a4ac0
to
5f84c46
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This PR contains the following updates:
14.2.24
->14.2.25
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2025-29927
Impact
It is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware.
Patches
15.2.3
14.2.25
13.5.9
12.3.5
Note: Next.js deployments hosted on Vercel are automatically protected against this vulnerability.
Workaround
If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the
x-middleware-subrequest
header from reaching your Next.js application.Credits
Release Notes
vercel/next.js (next)
v14.2.25
Compare Source
Configuration
📅 Schedule: Branch creation - "" in timezone GMT, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.