Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Dec 6, 2025

Critical vulnerability CVE-2025-55182 in React Server Components affects Next.js 15.x-16.x. Update required immediately per security advisory GHSA-9qr9-h5gf-34mp.

Changes

  • Updated next from 15.2.5 to 15.5.7 (patched release)
  • Regenerated pnpm-lock.yaml with new dependency resolution

Compatibility

Version 15.5.7 satisfies PayloadCMS peer dependency requirement ^15.2.3. No breaking changes or API modifications.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • cloud.nx.app
    • Triggering command: /usr/local/bin/node node ./bin/post-install (dns block)
    • Triggering command: /usr/local/bin/node node /home/REDACTED/work/codeware/codeware/node_modules/.bin/../nx/bin/nx.js build cms [email protected]_@swc+[email protected]_@swc+[email protected]__@swc+[email protected]_begefp6k6ctbuumylqz63a6khi/node_modules/nx/src/project-graph/plugins/isolation/plugin-worker (dns block)
    • Triggering command: /usr/local/bin/node node /home/REDACTED/work/codeware/codeware/node_modules/.bin/../nx/bin/nx.js lint cms (dns block)
  • fonts.googleapis.com
    • Triggering command: /usr/local/bin/node node /home/REDACTED/work/codeware/codeware/node_modules/.bin/../next/dist/bin/next build (dns block)

If you need me to access, download, or install something from one of these locations, you can either:


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

@bolt-new-by-stackblitz
Copy link

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

Copilot AI changed the title [WIP] Update Next.js to fix critical vulnerability fix(security): update Next.js to 15.5.7 for CVE-2025-55182 Dec 6, 2025
Copilot AI requested a review from hakalb December 6, 2025 11:02
@hakalb hakalb marked this pull request as ready for review December 6, 2025 13:10
Copilot AI review requested due to automatic review settings December 6, 2025 13:10
@nx-cloud
Copy link

nx-cloud bot commented Dec 6, 2025

View your CI Pipeline Execution ↗ for commit f407491

Command Status Duration Result
nx e2e nx-payload-e2e -c quick ❌ Failed 3m 5s View ↗
nx e2e nx-payload-e2e -c skip-docker ❌ Failed 1m 54s View ↗

☁️ Nx Cloud last updated this comment at 2025-12-06 13:30:18 UTC

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates Next.js from version 15.2.5 to 15.5.7, claiming to address a critical security vulnerability (CVE-2025-55182) in React Server Components. However, the validity of the referenced CVE and version should be verified before merging.

Key Changes:

  • Bumped next dependency version to 15.5.7 in package.json
  • Lock file regenerated with new dependency resolution (not shown in diff)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@codeware-actions
Copy link

✨ Your pull request project is ready for preview

Project App name Preview
web cdwr-web-pr-379 https://cdwr-web-pr-379.fly.dev

@codeware-actions
Copy link

✨ Your pull request project is ready for preview

Project App name Preview
web cdwr-web-pr-379 https://cdwr-web-pr-379.fly.dev

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants