Skip to content

fix: update vulnerable Next.js dependencies - #23

Draft
QuranRobot wants to merge 1 commit into
testingfrom
agent/fix-trivy-dependencies
Draft

fix: update vulnerable Next.js dependencies#23
QuranRobot wants to merge 1 commit into
testingfrom
agent/fix-trivy-dependencies

Conversation

@QuranRobot

Copy link
Copy Markdown

Summary

  • Upgrade Next.js from 13.1.4 to 15.5.16, addressing CVE-2026-44578.
  • Align eslint-config-next with 15.5.16 and update ESLint within the supported 8.x line.
  • Pin flatted 3.4.2 and refresh the Yarn lockfile.

Why

The public Open Graph service image contains the affected Next.js and flatted versions. Next.js 15.5.16 is the patched release identified by the fleet review.

Validation

  • git diff --check passes.
  • Branch is based on the current testing head.
  • Dependency install, Playwright tests, lint, and production build were not run in the isolated checkout; CI must pass before merge.

Risk

This is a major Next.js upgrade. Review route/rendering behavior and generated Open Graph images before promotion. No database or environment-variable changes are included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant