Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

nerdy-tech-com-gitub
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade next from 14.2.10 to 15.5.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 826 versions ahead of your current version.

  • The recommended version was released 25 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
140 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
140 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-NEXT-12299318
140 Proof of Concept
high severity Missing Authorization
SNYK-JS-NEXT-8520073
140 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
140 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
140 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIMECOREJS3-9397696
140 Proof of Concept
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
140 No Known Exploit
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
140 No Known Exploit
medium severity Race Condition
SNYK-JS-NEXT-10176058
140 Proof of Concept
medium severity Use of Cache Containing Sensitive Information
SNYK-JS-NEXT-12301496
140 No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-NEXT-8602067
140 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
140 Proof of Concept
low severity Missing Origin Validation in WebSockets
SNYK-JS-NEXT-10259370
140 No Known Exploit
low severity Missing Source Correlation of Multiple Independent Data
SNYK-JS-NEXT-12265451
140 No Known Exploit
critical severity Improper Authorization
SNYK-JS-NEXT-9508709
140 Mature
Release notes
Package name: next
  • 15.5.2 - 2025-08-26
  • 15.5.1 - 2025-08-26
  • 15.5.1-canary.39 - 2025-09-10
  • 15.5.1-canary.38 - 2025-09-10
  • 15.5.1-canary.37 - 2025-09-09
  • 15.5.1-canary.36 - 2025-09-09
  • 15.5.1-canary.35 - 2025-09-08
  • 15.5.1-canary.34 - 2025-09-08
  • 15.5.1-canary.33 - 2025-09-08
  • 15.5.1-canary.32 - 2025-09-07
  • 15.5.1-canary.31 - 2025-09-06
  • 15.5.1-canary.30 - 2025-09-05
  • 15.5.1-canary.29 - 2025-09-05
  • 15.5.1-canary.28 - 2025-09-04
  • 15.5.1-canary.27 - 2025-09-04
  • 15.5.1-canary.26 - 2025-09-04
  • 15.5.1-canary.25 - 2025-09-03
  • 15.5.1-canary.24 - 2025-09-02
  • 15.5.1-canary.23 - 2025-09-01
  • 15.5.1-canary.22 - 2025-08-31
  • 15.5.1-canary.21 - 2025-08-30
  • 15.5.1-canary.20 - 2025-08-29
  • 15.5.1-canary.19 - 2025-08-29
  • 15.5.1-canary.18 - 2025-08-29
  • 15.5.1-canary.17 - 2025-08-28
  • 15.5.1-canary.16 - 2025-08-28
  • 15.5.1-canary.15 - 2025-08-28
  • 15.5.1-canary.14 - 2025-08-27
  • 15.5.1-canary.13 - 2025-08-27
  • 15.5.1-canary.12 - 2025-08-27
  • 15.5.1-canary.11 - 2025-08-26
  • 15.5.1-canary.10 - 2025-08-26
  • 15.5.1-canary.9 - 2025-08-26

    Core Changes

    • feat(build): add client param parsing support for PPR routes: #82621

    Credits

    Huge thanks to @ wyattjoh for helping!

  • 15.5.1-canary.8 - 2025-08-25

    Core Changes

    • Unhook WebSocket: #82931
    • Destructure loadComponents where possible: #82986
    • optimize server action refresh logic: #82674

    Misc Changes

    • Turbopack: more incremental all_server_paths: #82892
    • Turbopack: throw large static metadata error earlier: #82939
    • Turbopack: don't treat metadata routes as RSC: #82911
    • Turbopack: remove blocking thread limit to avoid deadlocks: #82961
    • Update 07-fetching-data.mdx: #82862
    • Turbopack: fix race condition in unit test: #82989
    • Turbopack: support pattern into exports field: #82757
    • Turbopack: fix NFT tracing of sharp 0.34: #82340
    • Turbopack: skip db lookups on the initial build: #82405
    • Fetch tag before reset for create-release-branch: #83006
    • Update Rspack development test manifest: #82984
    • Update Rspack production test manifest: #82983
    • Ensure tags are fetched for release branch: #83012
    • Turbopack: prefetch restoring of task dependencies: #82960
    • Turbopack: add ffmpeg-static NFT test: #82985
    • temporarily disable flaky deploy test: #83032
    • fix: add '.next/types/**/*.ts' to the pages router TSConfig: #83029

    Credits

    Huge thanks to @ unstubbable, @ sokra, @ mischnic, @ sleekLancelot, @ ijjk, @ vercel-release-bot, @ timneutkens, @ ztanner, and @ bgub for helping!

  • 15.5.1-canary.7 - 2025-08-24

    Misc Changes

    • [turbopack] Optimize export const to bind readonly values not getters: #82760
    • fix: change "noUnknownAtRules" to "warn" for Biome: #82974

    Credits

    Huge thanks to @ lukesandberg and @ bgub for helping!

  • 15.5.1-canary.6 - 2025-08-23

    Misc Changes

    • Turbopack: Lazy decompress medium value compressed blocks: #82257
    • Turbopack: bigger small value blocks: #82370
    • Turbopack: remove value compression dictionary: #82338

    Credits

    Huge thanks to @ sokra for helping!

  • 15.5.1-canary.5 - 2025-08-22

    Core Changes

    • Add special marker in terminal if all error stack frames are ignore-listed: #82915
    • fix(edge-runtime): clone requests properly: #82878
    • Rename WebSocket file: #82930
    • fix: add path normalization to getRelativePath for Windows: #82918

    Misc Changes

    • Turbopack: add a CLI to NFT: #82815
    • Turbopack: print failing module during panic: #82938
    • [turbopack] Fix a few small things in the analyzer: #82899
    • Update Rspack production test manifest: #82925
    • Turbopack: parallel drop data before shutdown: #82335
    • Update Rspack development test manifest: #82924

    Credits

    Huge thanks to @ eps1lon, @ Kikobeats, @ mischnic, @ unstubbable, @ lukesandberg, @ vercel-release-bot, @ sokra, and @ bgub for helping!

  • 15.5.1-canary.4 - 2025-08-21

    Core Changes

    • Turbopack: fix the require.cache clear logic: #82876
    • Use deterministic env for public env vars: #82859
    • fix: typesafe linking to route handlers and pages API routes: #82858
    • fix: aliased navigations should apply scroll handling: #82900
    • Remove experimental appDocumentPreloading: #82895
    • Route modules: Call setReferenceManifestsSingleton for app-route to match app-page: #82908
    • Update prettier project dependency from 3.2.5 to 3.6.2: #82896
    • Do not modify parsedUrl collecting params: #82907
    • feat: add typesafety with config.typedRoutes to redirect() and permanentRedirect(): #82860
    • Skip emitting pages router entries when only app router present: #82444

    Misc Changes

    • Turbopack: sort keys in individual to make order deterministic: #82891
    • Turbopack: run more unit tests in multi thread runtime: #82889
    • Bump wasmer to 6.1.0-rc.3: #82885
    • Turbopack: run all unit tests with a fixed amount of worker threads to avoid overloading with many CPUs: #82890
    • Bump swc to v36: #82886
    • Update Rspack production test manifest: #82869
    • [turbopack] Add support for partial glob matches: #82906

    Credits

    Huge thanks to @ sokra, @ mischnic, @ bgub, @ ztanner, @ timneutkens, @ P41T0, @ vercel-release-bot, @ lukesandberg, @ ijjk, and @ huozhi for helping!

  • 15.5.1-canary.3 - 2025-08-21

    Misc Changes

    • Turbopack: use parallel execution helpers: #82667
    • Turbopack: allow to customize the parallel execution of turbo-persistence: #82668
    • Turbopack: use block in place for db writes: #82380
    • Turbopack: improve compaction: #82375
    • Turbopack: sync NFT context configs: #82781
    • Turbopack: fix invalid NFT entry with file behind symlink: #82887

    Credits

    Huge thanks to @ sokra and @ mischnic for helping!

  • 15.5.1-canary.2 - 2025-08-20

    Example Changes

    • docs: add missing RLS step to Next.js tutorial: #82714

    Misc Changes

    • fix: avoid importing types that will be unused: #82856
    • Turbopack: add parallel execution helpers: #82666

    Credits

    Huge thanks to @ bgub, @ Karthikeya-Thatipamula, and @ sokra for helping!

  • 15.5.1-canary.1 - 2025-08-20

    Core Changes

    • fix: missing next/link types with typedRoutes: #82814
    • [types] refactor shared types: #82844
    • fix: update the config.api.responseLimit type: #82852
    • fix: update validation return types: #82854

    Misc Changes

    • Update Rspack production test manifest: #82813
    • Turbopack: run unit tests in multi threaded runtime: #82665

    Credits

    Huge thanks to @ chungweileong94, @ vercel-release-bot, @ sokra, @ huozhi, and @ bgub for helping!

  • 15.5.1-canary.0 - 2025-08-20

    Core Changes

    • docs: mention turbopack config codemod: #82183
    • [devtools] Shim overlay on server: #82791
    • Turbopack: pass cache handler path as relative path to Rust: #82780
    • Remove unused code: #82774
    • [perf] only load next config once when start next dev server: #82654
    • [Cache Components] Error for Sync IO in Server Components during Static Prerender: #82500
    • Upgrade React from 0bdb9206-20250818 to 03fda05d-20250820: #82847

    Example Changes

    • fix: update @ types/node to resolve Vite 7.x peer dependency conflict: #82794

    Misc Changes

    • docs: fix typo in Image#priority: #82806
    • [test] update existing passed tests for cache components suite: #82830
    • [test] fix cache components build error in next-form tests: #82841

    Credits

    Huge thanks to @ wbinnssmith, @ charpeni, @ mischnic, @ timneutkens, @ huozhi, @ Hareesh108, and @ gnoff for helping!

  • 15.5.0 - 2025-08-20
  • 15.4.7 - 2025-08-18
  • 15.4.6 - 2025-08-06
  • 15.4.5 - 2025-07-29
  • 15.4.4 - 2025-07-24
  • 15.4.3 - 2025-07-22
  • 15.4.2 - 2025-07-18
  • 15.4.2-canary.56 - 2025-08-19
  • 15.4.2-canary.55 - 2025-08-19
  • 15.4.2-canary.54 - 2025-08-19
  • 15.4.2-canary.53 - 2025-08-18
  • 15.4.2-canary.52 - 2025-08-17
  • 15.4.2-canary.51 - 2025-08-16
  • 15.4.2-canary.50 - 2025-08-16
  • 15.4.2-canary.49 - 2025-08-15
  • 15.4.2-canary.48 - 2025-08-14
  • 15.4.2-canary.47 - 2025-08-14
  • 15.4.2-canary.46 - 2025-08-13
  • 15.4.2-canary.45 - 2025-08-13
  • 15.4.2-canary.44 - 2025-08-13
  • 15.4.2-canary.43 - 2025-08-13
  • 15.4.2-canary.42 - 2025-08-12
  • 15.4.2-canary.41 - 2025-08-12
  • 15.4.2-canary.40 - 2025-08-12
  • 15.4.2-canary.39 - 2025-08-12
  • 15.4.2-canary.38 - 2025-08-11
  • 15.4.2-canary.37 - 2025-08-11
  • 15.4.2-canary.36 - 2025-08-11
  • 15.4.2-canary.35 - 2025-08-09
  • 15.4.2-canary.34 - 2025-08-08
  • 15.4.2-canary.33 - 2025-08-07
  • 15.4.2-canary.32 - 2025-08-06
  • 15.4.2-canary.31 - 2025-08-05
  • 15.4.2-canary.30 - 2025-08-04
  • 15.4.2-canary.29 - 2025-08-03
  • 15.4.2-canary.28 - 2025-08-02
  • 15.4.2-canary.27 - 2025-08-01
  • 15.4.2-canary.26 - 2025-08-01
  • 15.4.2-canary.25 - 2025-07-31
  • 15.4.2-canary.24 - 2025-07-31
  • 15.4.2-canary.23 - 2025-07-31
  • 15.4.2-canary.22 - 2025-07-30
  • 15.4.2-canary.21 - 2025-07-30
  • 15.4.2-canary.20 - 2025-07-29
  • 15.4.2-canary.19 - 2025-07-28
  • 15.4.2-canary.18 - 2025-07-26
  • 15.4.2-canary.17 - 2025-07-25
  • 15.4.2-canary.16 - 2025-07-24
  • 15.4.2-canary.15 - 2025-07-23
  • 15.4.2-canary.14 - 2025-07-22
  • 15.4.2-canary.13 - 2025-07-22
  • 15.4.2-canary.12 - 2025-07-21
  • 15.4.2-canary.11 - 2025-07-21
  • 15.4.2-canary.10 - 2025-07-19
  • 15.4.2-canary.9 - 2025-07-18
  • 15.4.2-canary.8 - 2025-07-18
  • 15.4.2-canary.7 - 2025-07-17
  • 15.4.2-canary.6 - 2025-07-17
  • 15.4.2-canary.5 - 2025-07-16
  • 15.4.2-canary.4 - 2025-07-16
  • 15.4.2-canary.3 - 2025-07-16
  • 15.4.2-canary.2 - 2025-07-16
  • 15.4.2-canary.1 - 2025-07-15
  • 15.4.2-canary.0 - 2025-07-14
  • 15.4.1 - 2025-07-14
  • 15.4.0 - 2025-05-30
  • 15.4.0-canary.130 - 2025-07-14
  • 15.4.0-canary.129 - 2025-07-13
  • 15.4.0-canary.128 - 2025-07-12
  • 15.4.0-canary.127 - 2025-07-11
  • 15.4.0-canary.126 - 2025-07-11
  • 15.4.0-canary.123 - 2025-07-09
  • 15.4.0-canary.122 - 2025-07-09
  • 15.4.0-canary.121 - 2025-07-09
  • 15.4.0-canary.120 - 2025-07-09
  • 15.4.0-canary.119 - 2025-07-08
  • 15.4.0-canary.118 - 2025-07-08
  • 15.4.0-canary.116 - 2025-07-06
  • 15.4.0-canary.115 - 2025-07-05
  • 15.4.0-canary.114 - 2025-07-04
  • 15.4.0-canary.113 - 2025-07-03
  • 15.4.0-canary.112 - 2025-07-03
  • 15.4.0-canary.111 - 2025-07-03
  • 15.4.0-canary.110 - 2025-07-02
  • 15.4.0-canary.109 - 2025-07-02
  • 15.4.0-canary.108 - 2025-07-01
  • 15.4.0-canary.107 - 2025-07-01
  • 15.4.0-canary.106 - 2025-07-01
  • 15.4.0-canary.105 - 2025-07-01
  • 15.4.0-canary.104 - 2025-06-30
  • 15.4.0-canary.103 - 2025-06-29
  • 15.4.0-canary.102 - 2025-06-27
  • 15.4.0-canary.101 - 2025-06-27
  • 15.4.0-canary.100 - 2025-06-26
  • 15.4.0-canary.99 - 2025-06-26
  • 15.4.0-canary.98 - 2025-06-26
  • 15.4.0-canary.97 - 2025-06-26
  • 15.4.0-canary.96 - 2025-06-25
  • 15.4.0-canary.95 - 2025-06-24
  • 15.4.0-canary.94 - 2025-06-23
  • 15.4.0-canary.93 - 2025-06-23
  • 15.4.0-canary.92 - 2025-06-22
  • 15.4.0-canary.91 - 2025-06-21
  • 15.4.0-canary.90 - 2025-06-21
  • 15.4.0-canary.89 - 2025-06-20
  • 15.4.0-canary.88 - 2025-06-20
  • 15.4.0-canary.87 - 2025-06-19
  • 15.4.0-canary.86 - 2025-06-18
  • 15.4.0-canary.85 - 2025-06-18
  • 15.4.0-canary.84 - 2025-06-16
  • 15.4.0-canary.83 - 2025-06-14
  • 15.4.0-canary.82 - 2025-06-13
  • 15.4.0-canary.81 - 2025-06-13
  • 15.4.0-canary.80 - 2025-06-12
  • 15.4.0-canary.79 - 2025-06-11
  • 15.4.0-canary.78 - 2025-06-11
  • 15.4.0-canary.77 - 2025-06-11
  • 15.4.0-canary.76 - 2025-06-10
  • 15.4.0-canary.75 - 2025-06-10
  • 15.4.0-canary.74 - 2025-06-10
  • 15.4.0-canary.73 - 2025-06-09
  • 15.4.0-canary.72 - 2025-06-08
  • 15.4.0-canary.71 - 2025-06-07
  • 15.4.0-canary.70 - 2025-06-06
  • 15.4.0-canary.69 - 2025-06-06
  • 15.4.0-canary.68 - 2025-06-05
  • 15.4.0-canary.67 - 2025-06-04
  • 15.4.0-canary.66 - 2025-06-04
  • 15.4.0-canary.65 - 2025-06-04
  • 15.4.0-canary.64 - 2025-06-04
  • 15.4.0-canary.63 - 2025-06-03
  • 15.4.0-canary.62 - 2025-06-03
  • 15.4.0-canary.61 - 2025-06-01
  • 15.4.0-canary.60 - 2025-05-31
  • 15.4.0-canary.59 - 2025-05-30
  • 15.4.0-canary.58 - 2025-05-30
  • 15.4.0-canary.57 - 2025-05-29
  • 15.4.0-canary.56 - 2025-05-28
  • 15.4.0-canary.55 - 2025-05-27
  • 15.4.0-canary.54 - 2025-05-27
  • 15.4.0-canary.53 - 2025-05-26
  • 15.4.0-canary.52 - 2025-05-25
  • 15.4.0-canary.51 - 2025-05-24
  • 15.4.0-canary.50 - 2025-05-23
  • 15.4.0-canary.49 - 2025-05-23
  • 15.4.0-canary.48 - 2025-05-22
  • 15.4.0-canary.47 - 2025-05-21
  • 15.4.0-canary.46 - 2025-05-21
  • 15.4.0-canary.45 - 2025-05-21
  • 15.4.0-canary.44 - 2025-05-20
  • 15.4.0-canary.43 - 2025-05-20
  • ...

Snyk has created this PR to upgrade next from 14.2.10 to 15.5.2.

See this package in npm:
next

See this project in Snyk:
https://app.snyk.io/org/nerds-github/project/ee36eb20-a1af-42a9-95ba-e0bf3ed8d1c7?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants