-
Notifications
You must be signed in to change notification settings - Fork 0
fix(security): update Next.js to 15.5.7 for CVE-2025-55182 #379
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
|
Co-authored-by: hakalb <[email protected]>
|
View your CI Pipeline Execution ↗ for commit f407491
☁️ Nx Cloud last updated this comment at |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR updates Next.js from version 15.2.5 to 15.5.7, claiming to address a critical security vulnerability (CVE-2025-55182) in React Server Components. However, the validity of the referenced CVE and version should be verified before merging.
Key Changes:
- Bumped
nextdependency version to 15.5.7 in package.json - Lock file regenerated with new dependency resolution (not shown in diff)
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
✨ Your pull request project is ready for preview
|
|
✨ Your pull request project is ready for preview
|
Critical vulnerability CVE-2025-55182 in React Server Components affects Next.js 15.x-16.x. Update required immediately per security advisory GHSA-9qr9-h5gf-34mp.
Changes
nextfrom 15.2.5 to 15.5.7 (patched release)pnpm-lock.yamlwith new dependency resolutionCompatibility
Version 15.5.7 satisfies PayloadCMS peer dependency requirement
^15.2.3. No breaking changes or API modifications.Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
cloud.nx.app/usr/local/bin/node node ./bin/post-install(dns block)/usr/local/bin/node node /home/REDACTED/work/codeware/codeware/node_modules/.bin/../nx/bin/nx.js build cms [email protected]_@swc+[email protected]_@swc+[email protected]__@swc+[email protected]_begefp6k6ctbuumylqz63a6khi/node_modules/nx/src/project-graph/plugins/isolation/plugin-worker(dns block)/usr/local/bin/node node /home/REDACTED/work/codeware/codeware/node_modules/.bin/../nx/bin/nx.js lint cms(dns block)fonts.googleapis.com/usr/local/bin/node node /home/REDACTED/work/codeware/codeware/node_modules/.bin/../next/dist/bin/next build(dns block)If you need me to access, download, or install something from one of these locations, you can either:
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.