π¨ [security] Update next 15.2.6 β 15.5.6 (minor) #259
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ next (15.2.6 β 15.5.6) Β· Repo
Security Advisories π¨
π¨ Next.js is vulnerable to RCE in React flight protocol
π¨ Next.js is vulnerable to RCE in React flight protocol
π¨ Next.js Content Injection Vulnerability for Image Optimization
π¨ Next.js Affected by Cache Key Confusion for Image Optimization API Routes
π¨ Next.js Improper Middleware Redirect Handling Leads to SSRF
π¨ Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Release Notes
Too many releases to show here. View the full release notes.
Sorry, we couldn't find anything useful about this release.
Release Notes
1.7.1
1.7.0
1.6.0
1.5.0
1.4.5
1.4.3
1.4.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 54 commits:
1.7.1feat: support SharedArrayBuffer in napi_create_dataview (#183)move Node-API version detection (#182)1.7.0[Backport] feat: add napi_create_object_with_properties method (#181)ci: fix version retrieval1.6.0feat: make napi_delete_reference use node_api_basic_env (#170)[Backport] feat: added SharedArrayBuffer api (#171)ci: migrate to npm trusted publishing (#168)fix cifix ci1.5.0[Backport] build: backport emscripten parse tools changes to v1 (#165)fix: signature mismatch[Backport] fix(wasi): avoid deadlock caused by child thread abort when the main thread is in `Atomics.wait` (#163)[Backport] fix: env undefined after emitting beforeExit event (#162)1.4.5fix(wasm32-wasip1-threads): process never exit if trap in threads (#156)1.4.4fix: `worker.onerror` may receive an `Event`1.4.31.4.2fix: check SharedArrayBuffer (#144)1.4.1add checks for message channel usage in web runtime (#142)1.4.0perf: reduce the overhead of binding function call (#139)build: fix spawning `.bat` on Windowsupdate learn-wasm.dev linkadd learn-wasm.dev linktest: fix operator delete overloadrefactor: store external value in separated WeakMap (#134)test: build napi version 10define version 10 (#133)explicitly specify emnapiInit in testexplicitly specify emnapiInit in documentationremove deprecated attribute from napi_module_register (#132)allow napi_delete_reference in basic finalizers (#130)1.3.1update readmeadd missing source to gyp configadd missing source to js entryadd napi_create_buffer_from_arraybuffer (#126)fix: `napi_is_buffer(Uint8Array)` should return `true` (#129)1.3.0remove uv redefined macrosupdate uv sourceadd support for UTF-8 and Latin-1 property keys (#127)refactor: remove RefBase (#122)update libuv source (#121)refactor: rename nogc to basic (#125)feat: add suppressDestroy to context (#124)update dependencies (#123)Release Notes
Too many releases to show here. View the full release notes.
Sorry, we couldn't find anything useful about this release.
Commits
See the full diff on Github. The new version differs by 15 commits:
Release v2.1.2Ensure Node.js 10 and 12 can use async file-based detection methods (#33)Add semi-automated changelog #32Release v2.1.1Ensure Node.js 10 and 12 can use file-based detection methods (#30)Release v2.1.0CI: Add non-Linux integration tests for completenessPrerelease v2.1.0-rc.0CI: Publish tagged commits to npmDetect libc using the interpreter value from Node's ELF headerCI: update integration test expectationsRelease v2.0.4TypeScript: Add types field to package.json (#28)CI: remove Node.js 22CI: Add Node.js 20/22, remove CentOS (EOL)Release Notes
7.7.3
7.7.2
7.7.1
7.7.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 26 commits:
chore: release 7.7.3 (#812)fix: faster paths for compare (#813)fix: x-range build metadata supportchore: bump @npmcli/template-oss from 4.25.0 to 4.25.1 (#807)chore: bump @npmcli/template-oss from 4.24.4 to 4.25.0 (#797)chore: bump @npmcli/template-oss from 4.24.3 to 4.24.4 (#790)chore: release 7.7.2 (#783)fix: add missing `'use strict'` directives (#780)chore: template-oss-apply for workflow permissions (#784)fix: prerelease identifier starting with digits (#781)chore: bump @npmcli/template-oss from 4.23.6 to 4.24.3 (#778)chore: bump @npmcli/template-oss from 4.23.4 to 4.23.6 (#760)chore: release 7.7.1 (#765)fix(inc): fully capture prerelease identifier (#764)chore: release 7.7.0 (#750)fix(diff): fix prerelease to stable version diff logic (#755)chore: bump @npmcli/template-oss from 4.23.3 to 4.23.4 (#747)fix: add identifier validation to `inc()` (#754)feat: add "release" inc type (#753)docs(readme): added missing period for consistency (#756)docs: clarify comment about obsolete prefixes (#749)chore: bump @npmcli/eslint-config from 4.0.5 to 5.0.0chore: postinstall for dependabot template-oss PRchore: bump @npmcli/template-oss from 4.23.1 to 4.23.3chore: bump @npmcli/template-oss from 4.22.0 to 4.23.1chore: bump @npmcli/template-oss from 4.22.0 to 4.23.1π @βimg/colour (added, 1.0.0)
π @βimg/sharp-libvips-linux-ppc64 (added, 1.2.4)
π @βimg/sharp-libvips-linux-riscv64 (added, 1.2.4)
π @βimg/sharp-linux-ppc64 (added, 0.34.5)
π @βimg/sharp-linux-riscv64 (added, 0.34.5)
π @βimg/sharp-win32-arm64 (added, 0.34.5)
π @βimg/sharp-darwin-arm64 (added, 0.34.5)
π @βimg/sharp-darwin-x64 (added, 0.34.5)
π @βimg/sharp-libvips-darwin-arm64 (added, 1.2.4)
π @βimg/sharp-libvips-darwin-x64 (added, 1.2.4)
π @βimg/sharp-libvips-linux-arm (added, 1.2.4)
π @βimg/sharp-libvips-linux-arm64 (added, 1.2.4)
π @βimg/sharp-libvips-linux-s390x (added, 1.2.4)
π @βimg/sharp-libvips-linux-x64 (added, 1.2.4)
π @βimg/sharp-libvips-linuxmusl-arm64 (added, 1.2.4)
π @βimg/sharp-libvips-linuxmusl-x64 (added, 1.2.4)
π @βimg/sharp-linux-arm (added, 0.34.5)
π @βimg/sharp-linux-arm64 (added, 0.34.5)
π @βimg/sharp-linux-s390x (added, 0.34.5)
π @βimg/sharp-linux-x64 (added, 0.34.5)
π @βimg/sharp-linuxmusl-arm64 (added, 0.34.5)
π @βimg/sharp-linuxmusl-x64 (added, 0.34.5)
π @βimg/sharp-wasm32 (added, 0.34.5)
π @βimg/sharp-win32-ia32 (added, 0.34.5)
π @βimg/sharp-win32-x64 (added, 0.34.5)
π sharp (added, 0.34.5)
ποΈ @βswc/counter (removed)
ποΈ busboy (removed)
ποΈ streamsearch (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands