Skip to content

chore(deps): bump eslint-config-next from 16.2.5 to 16.2.6 in /web - #7

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/eslint-config-next-16.2.6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/eslint-config-next-16.2.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor

Bumps eslint-config-next from 16.2.5 to 16.2.6.

Release notes

Sourced from eslint-config-next's releases.

v16.2.6

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.

Security Fixes

The following advisories have been addressed:

High:

Moderate:

Low:

Core Changes

  • fix: preserve HTTP access fallbacks during prerender recovery (#92231)
  • Fix fallback route params case in app-page handler (#91737)
  • Fix invalid HTML response for route-level RSC requests in deployment adapter (#91541)
  • Patch setHeader for direct route handlers (#93101)
  • Include deployment id in cacheHandlers keys (#93453)
  • Fix double-encoding of URL pathname parts in client param parsing (#93491)
Commits

@dependabot @github

dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from acamarata as a code owner May 17, 2026 19:21
@vercel

vercel Bot commented May 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
islamwiki Ready Ready Preview, Comment May 17, 2026 7:45pm
ummat-islamwiki Ready Ready Preview, Comment May 17, 2026 7:45pm

Request Review

@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 10 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
next HIGH 1117930 Upgrade to version 16.2.5 or later
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later
next HIGH 1118949 Upgrade to version 16.2.5 or later
next HIGH 1118953 Upgrade to version 16.2.5 or later
next HIGH 1118955 Upgrade to version 16.2.5 or later
next HIGH 1118959 Upgrade to version 16.2.5 or later
next HIGH 1118961 Upgrade to version 16.2.5 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

Bumps [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) from 16.2.5 to 16.2.6.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](https://github.com/vercel/next.js/commits/v16.2.6/packages/eslint-config-next)

---
updated-dependencies:
- dependency-name: eslint-config-next
  dependency-version: 16.2.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump eslint-config-next from 16.2.4 to 16.2.6 in /web chore(deps): bump eslint-config-next from 16.2.5 to 16.2.6 in /web May 17, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/eslint-config-next-16.2.6 branch from 7a6f5d1 to 443ae9c Compare May 17, 2026 19:42
@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 4 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@dependabot @github

dependabot Bot commented on behalf of github Jun 3, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #18.

@dependabot dependabot Bot closed this Jun 3, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/web/eslint-config-next-16.2.6 branch June 3, 2026 04:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants