Skip to content

fix(deps): update dependency next to v14.2.30 [security]#1671

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-next-vulnerability
Jun 16, 2025
Merged

fix(deps): update dependency next to v14.2.30 [security]#1671
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-next-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 16, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
next (source) 14.2.26 -> 14.2.30 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-48068

Summary

A low-severity vulnerability in Next.js has been fixed in version 15.2.2. This issue may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects local development environments and requires the user to visit a malicious webpage while npm run dev is active.

Because the mitigation is potentially a breaking change for some development setups, to opt-in to the fix, you must configure allowedDevOrigins in your next config after upgrading to a patched version. Learn more.

Learn more: https://vercel.com/changelog/cve-2025-48068

Credit

Thanks to sapphi-red and Radman Siddiki for responsibly disclosing this issue.


Release Notes

vercel/next.js (next)

v14.2.30

Compare Source

v14.2.29

Compare Source

v14.2.28

Compare Source

v14.2.27

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • fix dynamic route interception not working when deployed with middleware (#​64923)
Credits

Huge thanks to @​ztanner for helping!


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/London, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cypress

cypress Bot commented Jun 16, 2025

Copy link
Copy Markdown

BanManager-WebUI    Run #8907

Run Properties:  status check passed Passed #8907  •  git commit e8bf1813c5 ℹ️: Merge 181c2b966c93ed81854d9a8d4c50dc14f5a796aa into 90d0b076e216b8af1dbb3fc6d9b1...
Project BanManager-WebUI
Branch Review refs/pull/1671/merge
Run status status check passed Passed #8907
Run duration 00m 44s
Commit git commit e8bf1813c5 ℹ️: Merge 181c2b966c93ed81854d9a8d4c50dc14f5a796aa into 90d0b076e216b8af1dbb3fc6d9b1...
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 15
View all changes introduced in this branch ↗︎

@renovate renovate Bot merged commit e28dd21 into master Jun 16, 2025
8 checks passed
@renovate renovate Bot deleted the renovate/npm-next-vulnerability branch June 16, 2025 19:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants