Skip to content

chore(deps): update dependency next to v14.2.30 [security] #9214

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 29, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
next (source) 14.2.28 -> 14.2.30 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2025-48068

Summary

A low-severity vulnerability in Next.js has been fixed in version 15.2.2. This issue may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects local development environments and requires the user to visit a malicious webpage while npm run dev is active.

Because the mitigation is potentially a breaking change for some development setups, to opt-in to the fix, you must configure allowedDevOrigins in your next config after upgrading to a patched version. Learn more.

Learn more: https://vercel.com/changelog/cve-2025-48068

Credit

Thanks to sapphi-red and Radman Siddiki for responsibly disclosing this issue.


Release Notes

vercel/next.js (next)

v14.2.30

Compare Source

v14.2.29

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label May 29, 2025
Copy link

nx-cloud bot commented May 29, 2025

View your CI Pipeline Execution ↗ for commit e2049bf.

Command Status Duration Result
nx affected --targets=test:sherif,test:knip,tes... ❌ Failed 3m 18s View ↗
nx run-many --target=build --exclude=examples/*... ❌ Failed 1m 44s View ↗

☁️ Nx Cloud last updated this comment at 2025-06-15 10:01:26 UTC

Copy link

pkg-pr-new bot commented May 29, 2025

More templates

@tanstack/angular-query-devtools-experimental

npm i https://pkg.pr.new/@tanstack/angular-query-devtools-experimental@9214

@tanstack/angular-query-experimental

npm i https://pkg.pr.new/@tanstack/angular-query-experimental@9214

@tanstack/eslint-plugin-query

npm i https://pkg.pr.new/@tanstack/eslint-plugin-query@9214

@tanstack/query-async-storage-persister

npm i https://pkg.pr.new/@tanstack/query-async-storage-persister@9214

@tanstack/query-broadcast-client-experimental

npm i https://pkg.pr.new/@tanstack/query-broadcast-client-experimental@9214

@tanstack/query-core

npm i https://pkg.pr.new/@tanstack/query-core@9214

@tanstack/query-devtools

npm i https://pkg.pr.new/@tanstack/query-devtools@9214

@tanstack/query-persist-client-core

npm i https://pkg.pr.new/@tanstack/query-persist-client-core@9214

@tanstack/query-sync-storage-persister

npm i https://pkg.pr.new/@tanstack/query-sync-storage-persister@9214

@tanstack/react-query

npm i https://pkg.pr.new/@tanstack/react-query@9214

@tanstack/react-query-devtools

npm i https://pkg.pr.new/@tanstack/react-query-devtools@9214

@tanstack/react-query-next-experimental

npm i https://pkg.pr.new/@tanstack/react-query-next-experimental@9214

@tanstack/react-query-persist-client

npm i https://pkg.pr.new/@tanstack/react-query-persist-client@9214

@tanstack/solid-query

npm i https://pkg.pr.new/@tanstack/solid-query@9214

@tanstack/solid-query-devtools

npm i https://pkg.pr.new/@tanstack/solid-query-devtools@9214

@tanstack/solid-query-persist-client

npm i https://pkg.pr.new/@tanstack/solid-query-persist-client@9214

@tanstack/svelte-query

npm i https://pkg.pr.new/@tanstack/svelte-query@9214

@tanstack/svelte-query-devtools

npm i https://pkg.pr.new/@tanstack/svelte-query-devtools@9214

@tanstack/svelte-query-persist-client

npm i https://pkg.pr.new/@tanstack/svelte-query-persist-client@9214

@tanstack/vue-query

npm i https://pkg.pr.new/@tanstack/vue-query@9214

@tanstack/vue-query-devtools

npm i https://pkg.pr.new/@tanstack/vue-query-devtools@9214

commit: cfdb81f

Copy link

Sizes for commit cfdb81f:

Branch Bundle Size
Main
This PR

Copy link

codecov bot commented May 29, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 47.01%. Comparing base (34eedd6) to head (cfdb81f).
Report is 36 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #9214      +/-   ##
==========================================
+ Coverage   45.24%   47.01%   +1.77%     
==========================================
  Files         209      209              
  Lines        8247     9127     +880     
  Branches     1859     2177     +318     
==========================================
+ Hits         3731     4291     +560     
- Misses       4076     4332     +256     
- Partials      440      504      +64     
Components Coverage Δ
@tanstack/angular-query-devtools-experimental ∅ <ø> (∅)
@tanstack/angular-query-experimental 85.45% <ø> (+0.40%) ⬆️
@tanstack/eslint-plugin-query 83.24% <ø> (ø)
@tanstack/query-async-storage-persister 43.85% <ø> (ø)
@tanstack/query-broadcast-client-experimental 24.39% <ø> (ø)
@tanstack/query-codemods 0.00% <ø> (ø)
@tanstack/query-core 98.00% <ø> (-0.13%) ⬇️
@tanstack/query-devtools 3.06% <ø> (-0.50%) ⬇️
@tanstack/query-persist-client-core 79.35% <ø> (+1.03%) ⬆️
@tanstack/query-sync-storage-persister 84.61% <ø> (ø)
@tanstack/query-test-utils 77.77% <ø> (ø)
@tanstack/react-query 96.39% <ø> (+0.39%) ⬆️
@tanstack/react-query-devtools 10.00% <ø> (ø)
@tanstack/react-query-next-experimental ∅ <ø> (∅)
@tanstack/react-query-persist-client 100.00% <ø> (ø)
@tanstack/solid-query 80.27% <ø> (+2.07%) ⬆️
@tanstack/solid-query-devtools ∅ <ø> (∅)
@tanstack/solid-query-persist-client 100.00% <ø> (ø)
@tanstack/svelte-query 87.09% <ø> (-1.07%) ⬇️
@tanstack/svelte-query-devtools ∅ <ø> (∅)
@tanstack/svelte-query-persist-client 100.00% <ø> (ø)
@tanstack/vue-query 73.35% <ø> (+2.49%) ⬆️
@tanstack/vue-query-devtools ∅ <ø> (∅)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate bot changed the title chore(deps): update dependency next to v15 [security] chore(deps): update dependency next to v15 [security] - autoclosed Jun 13, 2025
@renovate renovate bot closed this Jun 13, 2025
@renovate renovate bot deleted the renovate/npm-next-vulnerability branch June 13, 2025 15:28
@renovate renovate bot changed the title chore(deps): update dependency next to v15 [security] - autoclosed chore(deps): update dependency next to v15 [security] Jun 15, 2025
@renovate renovate bot reopened this Jun 15, 2025
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from b7dfada to cfdb81f Compare June 15, 2025 05:17
@renovate renovate bot changed the title chore(deps): update dependency next to v15 [security] chore(deps): update dependency next to v14.2.30 [security] Jun 15, 2025
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from cfdb81f to e2049bf Compare June 15, 2025 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants