[Snyk] Security upgrade next from 15.5.9 to 16.1.5 - #308
Closed
peterj wants to merge 1 commit into
Closed
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-NEXT-15104645 - https://snyk.io/vuln/SNYK-JS-NEXT-15105315
Contributor
|
Closing: this is now addressed on the
All 24 Next.js advisories that applied to 15.5.12 are fixed as of 15.5.21, so the 15.x line is sufficient — Superseded, and the Next 16 upgrade is deliberately not being taken here. Next 16 was attempted and blocked on four separate issues:
Since 15.5.21 fixes every advisory, staying on 15.x is the lower-risk path. A Next 16 upgrade should be its own PR with those four items handled. |
Contributor
Author
|
… On Wed, Aug 5, 2026 at 3:03 PM Kristin Brown ***@***.***> wrote:
*kristin-kronstain-brown* left a comment (kagent-dev/website#308)
<#308 (comment)>
Closing: this is now addressed on the kkb-hugo-docs-migration branch (#406
<#406>, commit 7adc835
<7adc835>),
which stays on the Next 15 line:
- next → ^15.5.21 (resolves 15.5.22)
- new overrides: postcss → ^8.5.23, sharp → ^0.35.0
All 24 Next.js advisories that applied to 15.5.12 are fixed as of 15.5.21,
so the 15.x line is sufficient — npm audit now reports next, postcss, and
sharp clean. Verified with npm ci and a full make build (Hugo docs +
OpenNext worker); CI is green on #406
<#406>.
Superseded, and the Next 16 upgrade is deliberately not being taken here.
Next 16 was attempted and blocked on four separate issues:
1. @***@***.*** peer conflict (ERESOLVE)
2. @***@***.*** incompatible with the Next 16 loader
3. Turbopack (the Next 16 default) rejects the non-serializable
remark/rehype plugin references in next.config.mjs, and ignores the
webpack: yaml-loader rule that 6 .yaml imports depend on
4. export const metadata is disallowed from the MDX client boundary,
affecting 68 page.mdx files
Since 15.5.21 fixes every advisory, staying on 15.x is the lower-risk
path. A Next 16 upgrade should be its own PR with those four items handled.
—
Reply to this email directly, view it on GitHub
<#308?email_source=notifications&email_token=ACURJ3FJSL3NGUDG4VQZ4UD5IMWDNA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMJZGIYDONBUGQ3KM4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2KYZTPN52GK4S7MNWGSY3L#issuecomment-5192074446>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACURJ3HNLRM5VWQKHB66VJD5IMWDNAVCNFSNUABFKJSXA33TNF2G64TZHM4TEMBRGYYTCOBQHNEXG43VMU5TGOBWGQ2DGOBXGQYKC5QC>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/ACURJ3EDML35MXZRR6YM3IL5IMWDNA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMJZGIYDONBUGQ3KM4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2KUZTPN52GK4S7NFXXG>
and Android
<https://github.com/notifications/mobile/android/ACURJ3FMWXHBH3QLIQKCMFL5IMWDNA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMJZGIYDONBUGQ3KM4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2K4ZTPN52GK4S7MFXGI4TPNFSA>.
Download it today!
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-NEXT-15104645
SNYK-JS-NEXT-15105315
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling