Skip to content

fix(dev-1693): bump next to 15.5.24 - #75

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1693
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1693

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

next is resolved at 15.3.1 in pnpm-lock.yaml (auto-installed peer of monocle-nextjs, not a direct dependency in any package.json). 30 open Dependabot advisories against this package/manifest (GHSA-2xp9-vwfh-vxw4 and 29 others — see the footer and DEV-1693 for the full list) require versions up to 15.5.24. No Dependabot PR exists for this finding. Bumped via a root pnpm.overrides entry (next: ^15.5.24) since next is a transitive/peer dependency, then regenerated the lockfile with pnpm install --lockfile-only. Resolved to 15.5.27, which satisfies every advisory's first_patched_version in the batch.

Three additional low-severity next advisories on this same manifest (GHSA-vfv6-92ff-j949, GHSA-3g8h-86w9-wvmq, GHSA-r2fc-ccr8-96c4) are tracked separately as risk-accept-proposal in DEV-1694 and are incidentally resolved by this same bump.

Test evidence

No Dependabot PR existed to replay; constructed from first_patched_version 15.5.24 (the highest across the batch). CI will run on this PR (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check).

Risk

Medium. This is a dependency-lockfile-only change via a pnpm.overrides entry, scoped to the next package. No source files are touched. next is a peer dependency of monocle-nextjs's build/test; CI's build and test steps exercise that path.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Oct 7, 2026

@spur-vuln-reviewer spur-vuln-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: diff scope limited to package.json + pnpm-lock.yaml (gate3-check.sh PASS, target=next pr_version=15.5.27 meets required=15.5.24, alerts 4,8,9,10,22,23,24,26,28,43,45,55,56,57,58,59,61,62,63,64,65,66,67,71,92,93,94,95,96,97,98,122,123, no extra files/deps). No .github/ changes. CI green (Linting, CodeQL x2, Unit Tests all SUCCESS). All commits authored by spur-vuln-author[bot].

@spur-vuln-reviewer

Copy link
Copy Markdown

merge-conflict: this PR was approved and passed all gates, but merging PR #78 (also pnpm-lock.yaml) ahead of it in this same pass changed main such that mergeStateStatus is now DIRTY (merge conflict). The approval stands; not merged. A human must review this (rebase/regenerate the lockfile). This reviewer will not act on this PR again.

[[spur-vuln-reviewer: escalated merge-conflict]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants