[Snyk] Security upgrade next from 15.3.5 to 16.3.0 - #33
RealSollyM wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-POSTCSS-18313036 - https://snyk.io/vuln/SNYK-JS-POSTCSS-18313038 - https://snyk.io/vuln/SNYK-JS-POSTCSS-18512282 - https://snyk.io/vuln/SNYK-JS-POSTCSS-16189065
|
The upgrade from Next.js v15 to v16 is a major version jump that introduces significant breaking changes and requires a migration to React 19. Vercel provides a codemod to automate many of the required updates, indicating the complexity of the migration. Key Breaking Changes:
Source: Next.js 16 Upgrade Guide Recommendation: This is a high-effort migration. It is strongly recommended to run the official codemod (
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9ca04a2864
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "input-otp": "^1.4.2", | ||
| "lucide-react": "^0.525.0", | ||
| "next": "15.3.5", | ||
| "next": "16.3.0", |
There was a problem hiding this comment.
Commit the Bun lockfile update for this upgrade
This bumps package.json, but the committed bun.lock still records the workspace dependency as "next": "15.3.5" and the resolved package as next@15.3.5, including the old nested postcss version. Because this repo commits bun.lock, any install/build path that relies on the checked-in Bun lockfile or uses a frozen install (Bun help: --frozen-lockfile Disallow changes to lockfile) will either keep using the vulnerable Next version or fail instead of applying the intended security fix. Please regenerate and commit bun.lock with the Next 16.3.0 resolution.
Useful? React with 👍 / 👎.
Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-POSTCSS-18313036
SNYK-JS-POSTCSS-18313038
SNYK-JS-POSTCSS-18512282
SNYK-JS-POSTCSS-16189065
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS)
🦉 Directory Traversal