Skip to content

Commit 04ecedd

Browse files
authored
Merge pull request #982 from cipherstash/fix/cip-4093-next
fix(deps): bump next to 15.5.24
2 parents ba410d1 + aca5cc8 commit 04ecedd

2 files changed

Lines changed: 54 additions & 53 deletions

File tree

‎pnpm-lock.yaml‎

Lines changed: 51 additions & 51 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎pnpm-workspace.yaml‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ catalogs:
6262
'@vitest/coverage-v8': 3.2.7
6363
security:
6464
'@clerk/nextjs': 7.7.7
65-
next: 15.5.23
65+
next: 15.5.24
6666
vite: 8.2.1
6767

6868
# Security overrides for Dependabot alerts on transitive deps that Dependabot
@@ -80,7 +80,8 @@ catalogs:
8080
overrides:
8181
# #96, #115-#127 — Next.js middleware bypass / SSRF / DoS / XSS batch
8282
# (GHSA-267c-6grr-h53f, GHSA-26hh-7cqf-hhc6, GHSA-36qx-fr4f-26g5, et al.)
83-
'next@<15.5.18': '~15.5.18'
83+
# #213, #214 GHSA-2xp9-vwfh-vxw4 / CVE-2026-75604 (CRITICAL) — patched 15.5.24.
84+
'next@<15.5.24': '~15.5.24'
8485
# #87 GHSA-f23m-r3pf-42rh, #88 GHSA-r5fr-rjxr-66jc — lodash _.unset / _.template
8586
'lodash@<4.18.0': '^4.18.0'
8687
# #133 GHSA-qjx8-664m-686j — js-cookie attribute injection

0 commit comments

Comments
 (0)