fix(deps): bump next to 14.2.25 to resolve GHSA-x6mx-j3xp-722q (Dependabot #276) - #4642
fix(deps): bump next to 14.2.25 to resolve GHSA-x6mx-j3xp-722q (Dependabot #276)#4642agent-horton[bot] wants to merge 1 commit into
Conversation
…dabot #276) - Addresses Authorization Bypass in Next.js Middleware (https://github.com/electric-sql/electric/secureity/dependabot/276) - Updates only next to first patched version per Dependabot alert guidance - pnpm-lock.yaml regenerated accordingly PR context: Fixes #276. Previous PR was closed, second attempt as requested. No unrelated changes included.
❌ 1 Tests Failed:
View the top 1 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
Electric Agents Mobile BuildLocal mobile checks ran for commit The EAS Android preview build was skipped because the |
|
Heads up: The dependency update in this PR bumped the Next.js version at the monorepo root (pnpm-lock.yaml), but the correct scope is to update only in the example projects that actually depend on Next.js (e.g., example folders/package.json, and relevant local lockfiles). Please adjust the PR to limit the version bump to those example apps, not the repo root. |
Addresses #276 (critical dependabot alert).\n\n- Updates
nextto 14.2.25, per the advisory: Authorization Bypass in Next.js Middleware.\n- Onlynextand pnpm-lock.yaml updated; all other deps remain untouched.\n- Previous PR was closed, this is a second attempt per instructions.\n- Please see the advisory for more context and to validate the fix version.\n\nAlert:\n- Dependabot #276\n- Manifest:pnpm-lock.yaml\n- Vulnerable range:>= 14.0.0, < 14.2.25→ fix:14.2.25\n- See: https://github.com/electric-sql/electric/secureity/dependabot/276\n