security: vulnerability remediation - #127
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit ca7ccd8. Configure here.
ca7ccd8 to
9b223ba
Compare
ulziibay-kernel
left a comment
There was a problem hiding this comment.
Verified the bump against the advisory's first patched version; rebuilt on current main and confirmed the toolchain lock/build is clean. CI green.
9b223ba to
fe50059
Compare

Vulnerability Remediation
Fixed
Not Included
Deferred details
Note
Low Risk
Patch-level framework upgrade with no app code changes; typical post-merge smoke test of build and MCP routes is sufficient.
Overview
Security patch: bumps Next.js from 16.2.6 to 16.2.11 to address GHSA-4633-3j49-mh5q.
package.jsonnow requires^16.2.11;bun.lockpinsnext@16.2.11and updates matching@next/envand platform@next/swc-*optional packages. No application source changes.Reviewed by Cursor Bugbot for commit fe50059. Bugbot is set up for automated code reviews on this repo. Configure here.