Repository navigation
fix(deps): update nextjs monorepo to v16 - #51
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
6185896 to
5a580e5
Compare
5a580e5 to
7287e83
Compare
7287e83 to
74bff17
Compare
Micro-Learning Topic: Race condition (Detected by phrase)Matched on "race condition"A race condition is a flaw that produces an unexpected result when the timing of actions impact other actions. Try a challenge in Secure Code Warrior |
74bff17 to
b1ca36a
Compare
b1ca36a to
97962d8
Compare
97962d8 to
82c4ea7
Compare
82c4ea7 to
ec7031f
Compare
ec7031f to
9c4484f
Compare
9c4484f to
6dfb65f
Compare
6dfb65f to
d922293
Compare
d922293 to
e0e58bc
Compare
e0e58bc to
f7a4855
Compare
f7a4855 to
365d72c
Compare
8145b1f to
df7c932
Compare
ec09ad6 to
fccaf87
Compare
fccaf87 to
f2af33d
Compare
f2af33d to
0dfa6dd
Compare
0dfa6dd to
3ec37db
Compare
3ec37db to
08fe210
Compare
6c686c1 to
78c2ce5
Compare
78c2ce5 to
3d8f1f6
Compare
3d8f1f6 to
08a1510
Compare
8152946 to
0c3a65a
Compare
0c3a65a to
6bbf61a
Compare
f55e986 to
3e949d2
Compare
512160a to
2091484
Compare
2091484 to
6639b8a
Compare
98e072c to
34bb85b
Compare
Micro-Learning Topic: Cross-site scripting (Detected by phrase)Matched on "Cross-site scripting"Cross-site scripting vulnerabilities occur when unescaped input is rendered into a page displayed to the user. When HTML or script is included in the input, it will be processed by a user's browser as HTML or script and can alter the appearance of the page or execute malicious scripts in their user context. Try a challenge in Secure Code WarriorHelpful references
Micro-Learning Topic: Denial of service (Detected by phrase)Matched on "Denial of Service"The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed. There are many ways to make a service unavailable for legitimate users by manipulating network packets, programming, logical, or resources handling vulnerabilities, among others. Source: https://www.owasp.org/index.php/Denial_of_Service Try a challenge in Secure Code WarriorMicro-Learning Topic: Server-side request forgery (Detected by phrase)Matched on "Server-side request forgery"Server-Side Request Forgery (SSRF) vulnerabilities are caused when an attacker can supply or modify a URL that reads or sends data to the server. The attacker can create a malicious request with a manipulated URL, when this request reaches the server, the server-side code executes the exploit URL causing the attacker to be able to read data from services that shouldn't be exposed. Try a challenge in Secure Code Warrior |
Micro-Learning Topic: Information disclosure (Detected by phrase)Matched on "Information disclosure"Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data may be compromised without extra protection, such as encryption at rest or in transit, and requires special precautions when exchanged with the browser. Source: https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project Try a challenge in Secure Code Warrior |
| datasource | package | from | to | | ---------- | ------------------ | ------ | ------ | | npm | eslint-config-next | 14.2.1 | 16.3.8 | | npm | next | 14.2.1 | 16.3.8 |
This PR contains the following updates:
14.2.1→16.3.814.2.1→16.3.8Release Notes
vercel/next.js (eslint-config-next)
v16.3.8Compare Source
This release contains security fixes for the following advisories:
High:
Medium:
use cachefill can leak Draft Mode content into regular responses and persisted pagesLow:
v16.3.7Compare Source
Core Changes
Credits
Huge thanks to @lukesandberg for helping!
v16.3.6Compare Source
This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse
v16.3.5Compare Source
The following bug fixes have been backported. It does not include all pending features/changes on canary.
output: 'standalone'is used with an adapter (#98167)use cacheprerender signal retention (#98448)v16.3.4Compare Source
Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).
The following bug fixes have been backported. It does not include all pending features/changes on canary.
Credits
Huge thanks to @eps1lon, @mischnic, and @timneutkens for helping!
v16.3.3Compare Source
This release contains security fixes for the following advisories:
Critical:
v16.3.2Compare Source
Core Changes
Credits
Huge thanks to @lubieowoce, @unstubbable, @timneutkens, @mischnic, and @eps1lon for helping!
v16.3.1Compare Source
What's Changed
turbopack_ecmascriptandturbopack_wasm's embeded FS tointernal_assets_conditionsby @lukesandberg in #96655headers()view of the incoming request by @unstubbable in #97311'use cache'files by @unstubbable in #97312unstable_cacheby @unstubbable in #97313Full Changelog: vercel/next.js@v16.3.0...v16.3.1
v16.3.0Compare Source
Core Changes
{eval:true}in worker_threads constructors: #91666cacheComponents: #91711next internal post-buildCLI command for Turbopack database compaction: #91336Effectas a trait instead of a closure: #89080AggregateError.errorsin the error overlay: #91835varyParamstracking for Cached Navigations: #92113experimental.dynamicIOconfig: #92081entry-base.ts: #91527get_compilation_issuestool and NAPI method: #92062next devserver if.nextis deleted: #92135turbo_tasks::apply_effects, useEffects::applyinstead: #91858CURRENTand stale sst files: #92414minimumReleaseAgeExcludefor React and friends: #9253574568e86-20260328to404b38c7-20260408: #92536targetoption in React Compiler for Pages + React 18: #91500compilerOptions.pathsin tsconfigs withoutcompilerOptions.baseUrl: #92277@turbopack/base64module: #92549"use cache": #92736downlevelIteration: #92652baseUrl: #92653@next/swcbinary postinstall: #92813"use cache"args during final prerender: #92820moduleResolution: "node": #92654images.maximumResponseBodyapplies to local images too: #92920unstable_io: #92923'use cache'invocations: #91830'use cache': #93055'use cache'fill timeout configurable: #93070url.parse: #93208super(...)messages in Error subclass constructors: #93182__NEXT_ERROR_CODEacross the/_errorpage handoff: #93183next build: #93280export * as X from './self'in scope-hoisted modules: #93192expirevalue with blocking revalidation: #93211experimental.turbopackWorkerAssetPrefixto keep Workers same-origin whenassetPrefixis a CDN: #93271onErroronce: #93209other: #93206cacheHandlerskeys: #93453compilerOptions: #93377'use cache'module-scope deadlocks early in dev: #93500'use cache'deadlock probe worker: #93538Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.