Update dependency eslint-config-next to v15.5.25 - #381
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
PR Summary
|
03e3bb1 to
e64f556
Compare
e64f556 to
2dc5fff
Compare
2dc5fff to
b9721c4
Compare
b9721c4 to
39b7ae3
Compare
39b7ae3 to
5dc7569
Compare
5dc7569 to
7ecb619
Compare
7ecb619 to
f020f98
Compare
f020f98 to
06831d9
Compare
06831d9 to
f2b74cd
Compare
f2b74cd to
edcb032
Compare
a6b65a5 to
9f65105
Compare
9f65105 to
8583a26
Compare
8583a26 to
799d321
Compare
799d321 to
7aaf920
Compare
7aaf920 to
b161221
Compare
b161221 to
e50d713
Compare
98934d6 to
e50d713
Compare
e50d713 to
1ef2570
Compare
1ef2570 to
003e15e
Compare
| next@15.1.0: | ||
| resolution: {integrity: sha512-QKhzt6Y8rgLNlj30izdMbxAwjHMFANnLwDwZ+WQh5sMhyt4lEBqDK9QpvWHtIM4rINKPoJ8aiRZKg5ULSybVHw==} | ||
| engines: {node: ^18.18.0 || ^19.8.0 || >= 20.0.0} | ||
| deprecated: This version has a security vulnerability. Please upgrade to a patched version. See https://nextjs.org/blog/CVE-2025-66478 for more details. |
There was a problem hiding this comment.
🚩 Lockfile this PR regenerates records the shipped next@15.1.0 runtime as vulnerable (CVE-2025-66478) while the PR bumps only eslint-config-next
Flagged for verification — not a confirmed defect. Please confirm or dismiss the risk below.
At pnpm-lock.yaml:3327 the diff adds deprecated: This version has a security vulnerability... CVE-2025-66478 to next@15.1.0, but package.json:32 still pins "next": "15.1.0" and the app's own scripts (package.json:5-7 dev/build/start) plus the Vercel deploy path run that exact version. The PR updates only the sibling lint package (eslint-config-next 15.1.0 → 15.5.23, package.json:66) — i.e., its own diff now asserts the app's runtime is insecure, and the eslint rules were also bumped 4 minor versions ahead of the runtime they lint. The lockfile resolution itself is internally consistent (peer deps satisfied, snapshot at pnpm-lock.yaml:6925 matches), so this is a verification request rather than a proven break: please confirm whether next should be bumped in lockstep with eslint-config-next (the Next.js release train pairs them), and whether the pinned 15.1.0 runtime is intentionally left on the known-vulnerable version.
| deprecated: This version has a security vulnerability. Please upgrade to a patched version. See https://nextjs.org/blog/CVE-2025-66478 for more details. | |
| next: "15.5.23" |
Code Terrier · flag · medium — reply Adopted / Skipped / Escalate in this thread. React 👍 / 👎 for feedback.
This PR contains the following updates:
15.1.0→15.5.25Release Notes
vercel/next.js (eslint-config-next)
v15.5.25Compare Source
Follow-up release to v15.5.24 re-enabling AVIF Image Optimization when newer versions of
sharpare installed (#97954).v15.5.24Compare Source
v15.5.23Compare Source
v15.5.22Compare Source
v15.5.21Compare Source
v15.5.20Compare Source
Contains no changes except publishing
@next/swc-wasm-webwhich was accidentally not published since 15.5.15.v15.5.19: 15.5.19Compare Source
Core Changes
FormDataentries (#94244)Other
Credits
Huge thanks to @eps1lon for helping!
v15.5.18Compare Source
This release contains security fixes for the following advisories:
High:
Moderate:
Low:
v15.5.16Compare Source
This release contains security fixes for the following advisories:
High:
Moderate:
Low:
v15.5.15Compare Source
Please refer the following changelogs for more information about this security release:
https://vercel.com/changelog/summary-of-cve-2026-23869
v15.5.14Compare Source
Core Changes
Credits
Huge thanks to @styfle and @lllomh for helping!
v15.5.13Compare Source
Core Changes
Credits
Huge thanks to @ztanner for helping!
v15.5.12Compare Source
This is a re-release of v15.5.11 applying the turbopack changes.
v15.5.11Compare Source
Core Changes
Credits
Huge thanks to @timneutkens, @mischnic, @ztanner, and @wyattjoh for helping!
v15.5.10Compare Source
Please refer the following changelogs for more information about this security release:
v15.5.9Compare Source
Please see the Next.js Security Update for information about this security patch.
v15.5.8Compare Source
v15.5.7Compare Source
Please see CVE-2025-66478 for additional details about this release.
v15.5.6Compare Source
Core Changes
Credits
Huge thanks to @mischnic for helping!
v15.5.5Compare Source
Core Changes
experimental.middlewareClientMaxBodySizebody cloning limit (#84722)Misc Changes
Credits
Huge thanks to @devjiwonchoi, @ztanner, and @icyJoseph for helping!
v15.5.4Compare Source
Core Changes
Misc Changes
Credits
Huge thanks to @yiminghe, @huozhi, @devjiwonchoi, @mischnic, @lukesandberg, @ztanner, @icyJoseph, @leerob, @fufuShih, @dwrth, @aymericzip, @obendev, @molebox, @OoMNoO, @pontasan, @styfle, @HondaYt, @ryuapp, @lpalmes, and @ijjk for helping!
v15.5.3Compare Source
Core Changes
Credits
Huge thanks to @bgub for helping!
v15.5.2Compare Source
Core Changes
Credits
Huge thanks to @bgub and @ztanner for helping!
v15.5.1Compare Source
Core Changes
Credits
Huge thanks to @bgub, @mischnic, and @ztanner for helping!
v15.5.0Compare Source
Core Changes
@typescript-eslint/switch-exhaustiveness-checkrule: #81583React.unstable_postpone(): #81652images.qualitiesis undefined: #81690pprordynamicIOenabled: #81668__turbopack_load_by_url__: #8166397cdd5d3-20250710to2f0e7e57-20250715: #81678renderToStringfunction: #817072f0e7e57-20250715tod85ec5f5-20250716: #81708next-serverVM: #81664headers/cookies/draftModein'use cache': #81716d85ec5f5-20250716todffacc7b-20250717: #81767getExpectedRequestStorefunction: #81791.next/cache: #81807dffacc7b-20250717toe9638c33-20250721: #81899'use cache: private': #81816browserslist: #81851run-turbopack-compilertrace span: #81917e9638c33-20250721to7513996f-20250722: #819407513996f-20250722toedac0dde-20250723: #81984exhaustive-depsviolations: #82010edac0dde-20250723to3d14fcf0-20250724: #820203d14fcf0-20250724to19baee81-20250725: #8206319baee81-20250725toeaee5308-20250728: #82120eaee5308-20250728to9be531cd-20250729: #82159@next/codemod: update docs url in README: #82135@next/codemod: Addexperimental.turbototurbopackcodemod for Next.js configs: #82134NextRequesttypes: #821729be531cd-20250729to9784cb37-20250730: #82207TURBOPACKenv before loading config: #82162outputFileTracingRootorturbopack.rootoption is provided: #821649784cb37-20250730toc260b38d-20250731: #82247eslint-plugin-react-hooksin React sync: #82294c260b38d-20250731tobe11cb5c-20250804: #82339_errorpage'sreq.urlcan be overwritten to dynamic param on minimal mode: #82347asPathfor query-only navigation withuseRouter: #82236?dplto fonts in/_next/static/media: #82384be11cb5c-20250804to7deda941-20250804: #82373pathto Image documentation: #823297deda941-20250804to3958d5d8-20250807: #824473958d5d8-20250807tof1e70b5e-20250811: #82534f1e70b5e-20250811toac7820a9-20250811: #82543image-sizepkg as additional format detector: #82538?dplto fonts in/_next/static/mediapart 2: #82488componentStackFramesfield: #82395skipMetadata: #82569ac7820a9-20250811to1dc3bdea-20250812: #82575Mapsupport fromnext/dynamictransform: #82487window.next.turbopackinstead: #825801dc3bdea-20250812tof1222f76-20250812: #82595f1222f76-20250812to379a083b-20250813: #82642turbo_tasks::spawn: #82634379a083b-20250813toa96a0f39-20250815: #82691turbopack.rootvalue foroutputFileTracingRootto have consistent tracing root: #82653Example Changes
with-supabaseexample to usegetClaims(): #81383Misc Changes
beforePageLoadto be async: #81650ImportedBindingeffect creation to avoid as much special-casing of SimpleAssignTarget: #81653use-cachetest suite in the Cache Components tests: #81610app-staticdeploy test: #81712requireto load chunks in our node runtime: #81738experimental.strictNextHead: #81882Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.