Skip to content

fix(web): patch dependency vulnerabilities, Next 16.2.10 to 16.3.5 - #2

Merged
dabelle merged 1 commit into
mainfrom
fix/web-dependency-vulns
Sep 16, 2026
Merged

dabelle merged 1 commit into
mainfrom
fix/web-dependency-vulns

Conversation

@dabelle

@dabelle dabelle commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator

npm audit reported 10 vulnerabilities on the web app, 1 critical and 6 high. Production dependencies are at zero after this.

The critical one is a proxy bypass in App Router. It applies here rather than being theoretical: src/proxy.ts is the only hard gate on /dashboard. The dashboard layout calls getUser() but renders conditionally instead of redirecting, so the proxy is the redirect. RLS still sits behind it, so a bypass would expose the shell rather than any data, but the gate should hold on its own.

The Next bump is non-breaking and also clears the postcss XSS and the sharp libvips CVEs, both inherited through it. npm audit fix covered brace-expansion, browserslist, js-yaml and baseline-browser-mapping.

Two moderate advisories remain against vitest. It is dev-only and never ships. The real fix is vitest 4.1.11, not the 2.0.5 downgrade npm suggests, but npm's resolver fails with an arborist error on that upgrade even under --dry-run. Regenerating the lockfile would likely clear it, and that is a large enough diff to deserve its own change rather than riding along with a security patch.

Verified locally: lint, tsc --noEmit, 48 tests, production build. The build output still registers the Proxy middleware.

Note this does nothing in production until a vercel deploy --prod, since git pushes do not trigger deploys on this project.

npm audit reported 10 vulnerabilities, 1 critical and 6 high. The critical
one is a proxy bypass in App Router (GHSA covers Turbopack + single locale),
which matters here because src/proxy.ts is the only hard gate on /dashboard:
the dashboard layout calls getUser() but renders conditionally rather than
redirecting, so the proxy is the redirect. RLS still stands behind it, so a
bypass exposes the shell rather than data, but the gate should hold on its
own.

The Next bump is non-breaking and also clears the postcss XSS and the sharp
libvips CVEs, which were inherited through it. npm audit fix handled
brace-expansion, browserslist, js-yaml and baseline-browser-mapping.

Production dependencies are now at zero. Two moderate advisories remain
against vitest, which is dev-only and never ships. The real fix is vitest
4.1.11, not the 2.0.5 downgrade npm suggests, but npm's resolver fails with
an arborist error on that upgrade even under --dry-run. Regenerating the
lockfile would likely clear it and belongs in its own change, not bundled
into a security patch.

Verified: lint, tsc --noEmit, 48 tests, and a production build.
@dabelle
dabelle merged commit 5138658 into main Sep 16, 2026
4 checks passed
@dabelle
dabelle deleted the fix/web-dependency-vulns branch September 16, 2026 00:46
dabelle pushed a commit that referenced this pull request Sep 19, 2026
fix(web): patch dependency vulnerabilities, Next 16.2.10 to 16.3.5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant