Skip to content

fix(security): bump Next.js 16.3.8 and pin high-severity transitives - #233

Merged
cursor[bot] merged 1 commit into
mainfrom
santosh/fix-weekly-security-audit-849b
Oct 5, 2026
Merged

cursor[bot] merged 1 commit into
mainfrom
santosh/fix-weekly-security-audit-849b

Conversation

@santoshkumarradha

@santoshkumarradha santoshkumarradha commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

Monday’s scheduled security workflow failed on main (1b84fe1, run 37295164642): pnpm audit (workspace), npm audit (docs-site), and therefore Security Success.

Related issue

Unblocks the weekly security cron. Dependabot PRs #230 / #232 do not cover these high/critical pins.

Changes

Workspace (pnpm.overrides)

  • next / eslint-config-next 16.3.4 → 16.3.8 — GHSA-vcvr-r3jv-pc5j critical RCE in next/og ImageResponse (fixed 16.3.6; 16.3.8 is the current 16.3 security line).
  • fast-uri 4.2.1, undici 8.11.2, brace-expansion >=5.0.11.
  • pnpm.auditConfig.ignoreGhsas: GHSA-vfj7-8cjw-p6xm (braces ≤3.0.3). No patched release exists. The only prod path is shadcn → fast-glob / micromatch at generate time, not a user-facing parser.

docs-site overrides

  • devalue ^5.9.3 (lock 5.9.4), http-cache-semantics ^4.3.0, undici ^8.10.2 (lock 8.11.2).

fix(security): so the next auto-release ships dashboard / customer-app images on Next 16.3.8.

Test plan

  • pnpm audit --audit-level=high --prod exits 0 (1 ignored: braces).
  • docs-site: npm audit --audit-level=high --omit=dev exits 0 (7 remaining Scalar/ai-sdk lows).
  • CI Success + Security Success (pnpm audit, docs-site npm audit, TypeScript lint/test, dashboard + customer-app image builds).

Notes for reviewers

Do not force-fix Scalar on the docs site (@scalar/api-reference-react@0.8.36 is a downgrade). Leave better-auth on 1.6.29.

Open in Web Open in Cursor 

Monday's security cron failed pnpm audit --prod and docs-site npm audit
on high/critical advisories:

- next 16.3.4: GHSA-vcvr-r3jv-pc5j (critical next/og RCE). Pin 16.3.8
  (Active LTS security line) plus matching eslint-config-next.
- fast-uri 4.1.3, undici 8.10.1, brace-expansion 5.0.9: override to
  patched releases.
- docs-site: devalue, http-cache-semantics, undici overrides.

Ignore GHSA-vfj7-8cjw-p6xm (braces <=3.0.3). There is no patched
release; the path is shadcn/fast-glob at build time, not a user-facing
parser.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: Santosh kumar <santoshkumarradha@users.noreply.github.com>
@santoshkumarradha
santoshkumarradha marked this pull request as ready for review October 5, 2026 10:26
@cursor
cursor Bot merged commit 0defadd into main Oct 5, 2026
31 checks passed
@cursor
cursor Bot deleted the santosh/fix-weekly-security-audit-849b branch October 5, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants