Skip to content

[Snyk] Security upgrade next from 15.5.7 to 15.5.9#107

Merged
Dargon789 merged 2 commits intomasterfrom
snyk-fix-7bb86781b87befff518483af74e78a7f
Dec 13, 2025
Merged

[Snyk] Security upgrade next from 15.5.7 to 15.5.9#107
Dargon789 merged 2 commits intomasterfrom
snyk-fix-7bb86781b87befff518483af74e78a7f

Conversation

@Dargon789
Copy link
Owner

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the pnpm dependencies of this project.

Snyk changed the following file(s):

  • extras/web/package.json
⚠️ Warning
Failed to update the pnpm-lock.yaml, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue
high severity Deserialization of Untrusted Data
SNYK-JS-NEXT-14400636
medium severity Exposure of Sensitive System Information to an Unauthorized Control Sphere
SNYK-JS-NEXT-14400644

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Deserialization of Untrusted Data

@bolt-new-by-stackblitz
Copy link

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@codesandbox
Copy link

codesandbox bot commented Dec 13, 2025

Review or Edit in CodeSandbox

Open the branch in Web EditorVS CodeInsiders

Open Preview

@vercel vercel bot temporarily deployed to Preview – sequence-js-docs December 13, 2025 16:17 Inactive
@vercel
Copy link

vercel bot commented Dec 13, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
sequence-js-docs Ready Ready Preview, Comment Dec 13, 2025 5:23pm
sequence-js-web Ready Ready Preview, Comment Dec 13, 2025 5:23pm

@snyk-io
Copy link

snyk-io bot commented Dec 13, 2025

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@gemini-code-assist
Copy link

Summary of Changes

Hello @Dargon789, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request, automatically generated by Snyk, aims to enhance the project's security posture by upgrading the 'next' framework dependency in the 'extras/web' package. This update specifically targets and remediates two identified vulnerabilities, one of high severity and one of medium severity, ensuring a more secure application environment.

Highlights

  • Security Upgrade: Updates the 'next' dependency from version '15.5.7' to '15.5.9' to address known security vulnerabilities.
  • Vulnerability Fixes: Resolves a high-severity 'Deserialization of Untrusted Data' vulnerability (SNYK-JS-NEXT-14400636) and a medium-severity 'Exposure of Sensitive System Information to an Unauthorized Control Sphere' vulnerability (SNYK-JS-NEXT-14400644).
  • Manual pnpm-lock.yaml Update Required: Notes that the 'pnpm-lock.yaml' file failed to update automatically and requires manual intervention before merging.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request, automatically generated by Snyk, upgrades the next package from version 15.5.7 to 15.5.9 to fix two security vulnerabilities. The change in extras/web/package.json is correct. However, as noted by Snyk, the pnpm-lock.yaml file has not been updated. This is a critical issue, as without updating the lockfile, the vulnerable version of next will still be used. You must run pnpm install to regenerate the lockfile before merging. Additionally, I've noticed that the extras/docs workspace also appears to be using the vulnerable version of next and should probably be updated as well to ensure consistency and security across the monorepo.

Repository owner deleted a comment from vercel bot Dec 13, 2025
Repository owner deleted a comment from vercel bot Dec 13, 2025
@Dargon789 Dargon789 merged commit 42b5d42 into master Dec 13, 2025
18 of 21 checks passed
@Dargon789 Dargon789 deleted the snyk-fix-7bb86781b87befff518483af74e78a7f branch December 13, 2025 17:27
@Dargon789 Dargon789 mentioned this pull request Dec 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants