security: vulnerability remediation - #127
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit ca7ccd8. Configure here.
ca7ccd8 to
9b223ba
Compare
ulziibay-kernel
left a comment
There was a problem hiding this comment.
Verified the bump against the advisory's first patched version; rebuilt on current main and confirmed the toolchain lock/build is clean. CI green.
9b223ba to
fe50059
Compare
fe50059 to
a0145e6
Compare
a0145e6 to
bab8eca
Compare
bab8eca to
d4d7b54
Compare

Vulnerability Remediation
Fixed
Not Included
Deferred details
Note
Low Risk
Patch-level Next.js upgrade with no app code changes; main residual risk is normal framework regression, so a quick
build/testpass is enough before merge.Overview
Security dependency bump for GHSA-4633-3j49-mh5q:
nextis raised from 16.2.6 to 16.2.11 inpackage.json(^16.2.11), withbun.lockupdated sonext,@next/env, and platform@next/swc-*binaries all resolve to 16.2.11.No application or config source files change—only manifests and the lockfile. Other deferred scanner findings are out of scope for this PR.
Reviewed by Cursor Bugbot for commit d4d7b54. Bugbot is set up for automated code reviews on this repo. Configure here.