Repository navigation
fix(dev-1693): bump next to 15.5.24 - #75
spur-vuln-author[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Verified: diff scope limited to package.json + pnpm-lock.yaml (gate3-check.sh PASS, target=next pr_version=15.5.27 meets required=15.5.24, alerts 4,8,9,10,22,23,24,26,28,43,45,55,56,57,58,59,61,62,63,64,65,66,67,71,92,93,94,95,96,97,98,122,123, no extra files/deps). No .github/ changes. CI green (Linting, CodeQL x2, Unit Tests all SUCCESS). All commits authored by spur-vuln-author[bot].
|
merge-conflict: this PR was approved and passed all gates, but merging PR #78 (also pnpm-lock.yaml) ahead of it in this same pass changed main such that mergeStateStatus is now DIRTY (merge conflict). The approval stands; not merged. A human must review this (rebase/regenerate the lockfile). This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated merge-conflict]] |
Context
nextis resolved at 15.3.1 inpnpm-lock.yaml(auto-installed peer ofmonocle-nextjs, not a direct dependency in anypackage.json). 30 open Dependabot advisories against this package/manifest (GHSA-2xp9-vwfh-vxw4 and 29 others — see the footer and DEV-1693 for the full list) require versions up to 15.5.24. No Dependabot PR exists for this finding. Bumped via a rootpnpm.overridesentry (next: ^15.5.24) sincenextis a transitive/peer dependency, then regenerated the lockfile withpnpm install --lockfile-only. Resolved to 15.5.27, which satisfies every advisory'sfirst_patched_versionin the batch.Three additional low-severity
nextadvisories on this same manifest (GHSA-vfv6-92ff-j949, GHSA-3g8h-86w9-wvmq, GHSA-r2fc-ccr8-96c4) are tracked separately as risk-accept-proposal in DEV-1694 and are incidentally resolved by this same bump.Test evidence
No Dependabot PR existed to replay; constructed from
first_patched_version15.5.24 (the highest across the batch). CI will run on this PR (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check).Risk
Medium. This is a dependency-lockfile-only change via a
pnpm.overridesentry, scoped to thenextpackage. No source files are touched.nextis a peer dependency ofmonocle-nextjs's build/test; CI's build and test steps exercise that path.