Skip to content

chore(deps): bump next to 16.3.3 - #6832

Open
mozilla-blender[bot] wants to merge 1 commit into
mainfrom
blender/security-bump-next
Open

mozilla-blender[bot] wants to merge 1 commit into
mainfrom
blender/security-bump-next

Conversation

@mozilla-blender

Copy link
Copy Markdown
Contributor

Summary

Resolves a flagged transitive dependency advisory.

This is a transitive dependency update. Only package-lock.json (and possibly package.json) changed.


Created by BLEnder investigation via BLEnder

Resolves Dependabot alert #303.
Created by BLEnder (https://github.com/mozilla/blender)
@mozilla-blender

Copy link
Copy Markdown
Contributor Author

BLEnder investigated: This dependency has an open security alert, but the repo is not affected.

next 16.3.0 is in range and App Router is self-hosted via next start, but this RCE requires a Windows filesystem host. All deploys are Linux (node:20-alpine on GCP Cloud Run, docker-compose linux/amd64, ubuntu-latest CI). Not exploitable here; bump still advised.

This PR can be reviewed and merged as a normal dependency update.

@mozilla-blender

Copy link
Copy Markdown
Contributor Author

BLEnder could not fix this PR automatically. Workflow run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants