fix(web): patch dependency vulnerabilities, Next 16.2.10 to 16.3.5 - #2
Merged
Merged
Conversation
npm audit reported 10 vulnerabilities, 1 critical and 6 high. The critical one is a proxy bypass in App Router (GHSA covers Turbopack + single locale), which matters here because src/proxy.ts is the only hard gate on /dashboard: the dashboard layout calls getUser() but renders conditionally rather than redirecting, so the proxy is the redirect. RLS still stands behind it, so a bypass exposes the shell rather than data, but the gate should hold on its own. The Next bump is non-breaking and also clears the postcss XSS and the sharp libvips CVEs, which were inherited through it. npm audit fix handled brace-expansion, browserslist, js-yaml and baseline-browser-mapping. Production dependencies are now at zero. Two moderate advisories remain against vitest, which is dev-only and never ships. The real fix is vitest 4.1.11, not the 2.0.5 downgrade npm suggests, but npm's resolver fails with an arborist error on that upgrade even under --dry-run. Regenerating the lockfile would likely clear it and belongs in its own change, not bundled into a security patch. Verified: lint, tsc --noEmit, 48 tests, and a production build.
dabelle
pushed a commit
that referenced
this pull request
Sep 19, 2026
fix(web): patch dependency vulnerabilities, Next 16.2.10 to 16.3.5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
npm auditreported 10 vulnerabilities on the web app, 1 critical and 6 high. Production dependencies are at zero after this.The critical one is a proxy bypass in App Router. It applies here rather than being theoretical:
src/proxy.tsis the only hard gate on/dashboard. The dashboard layout callsgetUser()but renders conditionally instead of redirecting, so the proxy is the redirect. RLS still sits behind it, so a bypass would expose the shell rather than any data, but the gate should hold on its own.The Next bump is non-breaking and also clears the postcss XSS and the sharp libvips CVEs, both inherited through it.
npm audit fixcovered brace-expansion, browserslist, js-yaml and baseline-browser-mapping.Two moderate advisories remain against vitest. It is dev-only and never ships. The real fix is vitest 4.1.11, not the 2.0.5 downgrade npm suggests, but npm's resolver fails with an arborist error on that upgrade even under
--dry-run. Regenerating the lockfile would likely clear it, and that is a large enough diff to deserve its own change rather than riding along with a security patch.Verified locally: lint,
tsc --noEmit, 48 tests, production build. The build output still registers the Proxy middleware.Note this does nothing in production until a
vercel deploy --prod, since git pushes do not trigger deploys on this project.