Repository navigation
Conversation
Bumps next to 16.3.8 (critical), eslint-config-next to 16.3.8, ip-address to 10.7.3, and the transitive brace-expansion, undici and source-map-js.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThree dependency versions changed in ChangesDependency version updates
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable merge risk is evident in the dependency updates; the lockfile matches the manifest, including its existing Node requirement. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the package list, Comment |
|
Superseded by the Tailwind 4 upgrade PR, which includes these dependency updates. |
|
Superseded by #838. |
Issue ticket number and link
No ticket. Consolidates the open Dependabot security PRs #826, #832, #833 and #835.
Documentation
Select exactly one:
Dependency updates only; no user-facing behavior changes.
Changes
nextundici(transitive)brace-expansion(transitive)source-map-js(transitive)ip-addresseslint-config-nextnextnextgoes to 16.3.8 rather than Dependabot's 16.3.6, becausenpm auditflags everything up to 16.3.5.nextstays pinned to an exact version.npm auditdrops from 14 vulnerabilities (1 critical, 10 high, 3 moderate) to 9 (7 high, 2 moderate).Not included
postcss-selector-parser(GHSA-rj75-hqrm-r3gf), which Tailwind 3 pins to v6.braces(GHSA-vfj7-8cjw-p6xm): no patched release exists. It reaches us through Tailwind 3 (chokidar,micromatch,fast-glob) and through@next/eslint-plugin-next, so even Tailwind 4 would not clear it.All remaining findings are in build and lint tooling that only processes our own source, not in the shipped bundle.
Verification
tsc --noEmitpasses.vitest run: 55 files, 769 tests pass.npm run buildsucceeds.npm run lintreports existingsimple-import-sortandreact-hookserrors. Those plugins are unchanged by this PR, so the errors are not introduced here.Summary by CodeRabbit