Skip to content

fix(security): #4693 — monter next-auth en 4.24.15 et next en 16.3.8 - #4751

Merged
maxgfr merged 2 commits into
alphafrom
issue-4693-deps-runtime-a
Oct 7, 2026
Merged

maxgfr merged 2 commits into
alphafrom
issue-4693-deps-runtime-a

Conversation

@maxgfr

@maxgfr maxgfr commented Oct 6, 2026

Copy link
Copy Markdown
Member

Closes #4693

Résumé

  • next-auth 4.24.13 → 4.24.15 (version exacte, comme avant). Corrige les trois CVE remontées par pnpm audit, dont la critique sur la normalisation d'email Unicode.
  • next 16.3.3 → 16.3.8. 16.3.3 est concerné par GHSA-vcvr-r3jv-pc5j (critique, RCE via next/og / ImageResponse, corrigée en 16.3.6). next/og n'est pas utilisé dans l'app, donc a priori pas exploitable, mais la version est montée au dernier correctif de la ligne 16.3. Remplace la PR Dependabot chore(deps): bump next from 16.3.3 to 16.3.6 #4719.

Cette PR ne touche que packages/app/package.json et le lockfile. Elle est à merger en premier dans le lot sécurité : les autres PR se rebasent sur ce lockfile.

Vérification

  • pnpm typecheck : OK
  • pnpm test : app 7206/7206, notifications 165/165
  • pnpm --filter app build (SKIP_ENV_VALIDATION=1) : OK sur Next.js 16.3.8
  • pnpm lint:check, pnpm format:check : OK
  • pnpm audit --prod : plus aucune alerte sur next ni next-auth. undici et le nodemailer transitif sont traités dans Sécurité : mettre à jour nodemailer (10.0.2) et undici (7.29.1) #4702.

Test plan

  • E2E complet (« Test e2e ») vert, en particulier connexion / déconnexion ProConnect
  • Review app : connexion ProConnect puis accès à Mon espace

next-auth 4.24.13 porte trois CVE (dont une critique sur la normalisation
d'email). next 16.3.3 est concerné par GHSA-vcvr-r3jv-pc5j (critique, corrigé
en 16.3.6) ; next/og n'est pas utilisé, mais la version est montée au dernier
correctif de la ligne 16.3.
@maxgfr
maxgfr had a problem deploying to build-review-auto October 6, 2026 12:24 — with GitHub Actions Failure
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Audit d'accessibilité ultra11y — RGAA

✅ Aucune non-conformité relevée par le moteur statique.

2026-10-07 · 355 fichiers · 2/106 critères tranchés dans ce run · 2 moteur · 104 à compléter par scan ou adjudication

Périmètre de ce run — 0 page rendue : aucun test rendered n'a été exécuté
27 test(s) static — critères : 1.1 · 2.1 · 5.7 · 5.8 · 6.2 · 7.1 · 8.2 · 8.3 · 8.4 · 8.5 · 8.10 · 9.3 · 10.1 · 10.12 · 11.1 · 11.5 · 11.6 · 11.8 · 11.9
3 test(s) rendered prévus — critères : 1.1 · 8.1 · 10.7
Couverture moteur : 49 critère(s) reçoivent un signal normatif — 21 critère(s) peuvent produire un NC décisif · 41 reçoivent des preuves candidates (avec chevauchement) · 1 autre reçoit une recommandation advisory
228 test(s) judgment sur 92 critère(s), tous transmis à l'IA tant qu'ils ne sont pas tranchés

Rapport complet (HTML, captures annotées) : artefact ultra11y-pr-static du run.

Voir le run et son résumé de job

@socket-security

socket-security Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​16.3.3 ⏵ 16.3.861100 +7590 +19970
Updatednext-auth@​4.24.13 ⏵ 4.24.1587 -10100 +7510094 +8100
Updatedundici@​7.24.8 ⏵ 7.30.093 +1100 +61100 +197100
Updatednodemailer@​9.0.6 ⏵ 10.0.1598 +3100 +2898 +296 +3100

View full report

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

🧪 Recette E2E — grille 185 coordonnées

Date Commit Périmètre Durée Résultat
2026-10-07 553dda9 tous les cas (185 coordonnées) 8m 28s 185 passés / 0 échoué / 0 non joué sur 185

➡️ Grille complète dans le résumé du run · Rapport Playwright et traces

@maxgfr
maxgfr had a problem deploying to build-review-auto October 6, 2026 12:50 — with GitHub Actions Failure
@maxgfr
maxgfr deployed to build-review-auto October 6, 2026 16:33 — with GitHub Actions Active
@maxgfr
maxgfr deployed to review-auto October 6, 2026 16:45 — with GitHub Actions Active
@maxgfr
maxgfr marked this pull request as ready for review October 7, 2026 09:48
@maxgfr
maxgfr requested review from LucasCharrier and Viczei and removed request for Viczei October 7, 2026 09:50

@iterion-forge-egapro iterion-forge-egapro Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Revi — aucun problème détecté dans le périmètre revu.

Détails du run IA · Iterion

Run : 01a115c3-8dd3-716a-9cdc-3f5ae605e04b

Tokens du run au moment de publier : 113 051.

Périmètre revu : correctness/security: packages/app/package.json — version specifiers (next ^16.2.11→^16.3.8, next-auth exact pin 4.24.13→4.24.15) ; data/integrity: pnpm-lock.yaml — importer resolutions, snapshot graph, integrity hashes cross-checked against the public npm registry (both match) ; compatibility: next-auth 4.24.15 transitive change uuid 8.3.2→11.1.1 (exists, no engines restriction; Next 16 requires node >=20.9.0) and peer ranges (next ^12.2.5||^13||^14||^15||^16 satisfied) ; requirements: GitHub issue #4693 fetched and compared to the diff

Revue mono (single model family).

Étape Modèle Harness Effort demandé Tokens
Revue GLM glm-5.3 claude_code max 67 303
Synthèse · GLM glm-5.3 claude_code medium 45 748

Tokens cumulés des appels IA, pas la taille du contexte. L’effort indiqué est le réglage demandé au modèle.

@LucasCharrier LucasCharrier left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mise à jour ciblée des dépendances et lockfile cohérent. Approuvé.

@Viczei

Viczei commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Retour de revue non bloquant — état consulté : 7db1f5e8c1f0b414cf5a173a969c71c30a5180e3.

Aucune anomalie bloquante identifiée dans la mise à jour de Next.js / NextAuth et du lockfile lors de la revue initiale. Ordre de fusion : cette PR précède #4756, qui est empilée dessus. La validation ne signifie pas que j'ai relancé personnellement la suite complète ou le parcours ProConnect.

Les points ouverts sont consignés en suivi et ne constituent pas une demande de changements de ma part.

@Viczei Viczei left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approbation avec les retours consignés en suivi non bloquant : #4751 (comment). Les points encore ouverts et les limites de vérification restent ceux du commentaire.

@maxgfr
maxgfr deployed to build-review-auto October 7, 2026 17:12 — with GitHub Actions Active
@maxgfr
maxgfr deployed to review-auto October 7, 2026 17:19 — with GitHub Actions Active
@maxgfr
maxgfr enabled auto-merge (squash) October 7, 2026 17:21
@tokenbureau

tokenbureau Bot commented Oct 7, 2026

Copy link
Copy Markdown

🎉 Deployment for commit 553dda9 :

Ingresses
Docker images
  • 📦 docker pull apache/apisix:3.11.0-debian
  • 📦 docker pull axllent/mailpit:v1.31.0
  • 📦 docker pull docker.io/valkey/valkey:9.0.2
  • 📦 docker pull haproxy:3.2.23-alpine3.24
  • 📦 docker pull harbor.fabrique.social.gouv.fr/egapro/egapro/app:sha-553dda9b37ab3dc9ec6578e37ee577d2d549a602
Debug

@maxgfr
maxgfr merged commit 98025f9 into alpha Oct 7, 2026
35 checks passed
@maxgfr
maxgfr deleted the issue-4693-deps-runtime-a branch October 7, 2026 17:25

This branch was successfully deployed

2 active deployments
build-review-auto — 553dda9b Deployed Oct 7, 2026 by maxgfr via build-app #6623
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sécurité : mettre à jour next-auth 4.24.13 → 4.24.15 (CVE critique)

3 participants