Skip to content

fix(security): patch path-to-regexp (high) and upgrade Next.js to 16.2.1#17

Merged
otonielrojas merged 1 commit intomasterfrom
fix/security-remaining
Mar 28, 2026
Merged

fix(security): patch path-to-regexp (high) and upgrade Next.js to 16.2.1#17
otonielrojas merged 1 commit intomasterfrom
fix/security-remaining

Conversation

@otonielrojas
Copy link
Copy Markdown
Owner

Summary

Result

npm audit reports 0 vulnerabilities after these changes.

Test plan

  • 26/26 unit tests pass locally

🤖 Generated with Claude Code

Fixes 2 remaining vulnerabilities after Dependabot PRs merged:
- path-to-regexp: DoS via sequential optional groups / multiple wildcards (high)
- next 16.1.6 → 16.2.1: HTTP smuggling, CSRF bypass, DoS issues (moderate)

All 26 unit tests pass.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@otonielrojas otonielrojas merged commit 4ce7d2d into master Mar 28, 2026
1 check failed
@otonielrojas otonielrojas deleted the fix/security-remaining branch March 28, 2026 19:53
@netlify
Copy link
Copy Markdown

netlify bot commented Mar 28, 2026

Deploy Preview for spendable ready!

Name Link
🔨 Latest commit 681beab
🔍 Latest deploy log https://app.netlify.com/projects/spendable/deploys/69c831c093e9bb0008e0f319
😎 Deploy Preview https://deploy-preview-17--spendable.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant