Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

fix(deps): update dependency next to v15.2.4 [security]#522

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
Slashgear merged 1 commit intomasterfromrenovate/npm-next-vulnerability
Jul 28, 2025

Conversation

@renovate
Copy link
Contributor

@renovaterenovatebot commentedApr 3, 2025
edited
Loading

This PR contains the following updates:

PackageChangeAgeConfidence
next (source)15.2.3 ->15.2.4ageconfidence

GitHub Vulnerability Alerts

CVE-2025-30218

Summary

In the process of remediatingCVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers.

Learn morehere.

Credit

Thank you to Jinseo Kimkjsman and RyotaK (GMO Flatt Security Inc.) withtakumi-san.ai for the responsible disclosure. These researchers were awarded as part of our bug bounty program.


Release Notes

vercel/next.js (next)

v15.2.4

Compare Source

[!NOTE]
This release is backporting bug fixes. It doesnot include all pending features/changes on canary.

Core Changes
  • Match subrequest handling for edge and node (#​77474)
  • exclude images and static media from dev origin check (#​77417)
  • ensure /__next middleware URLs are included in the origin check (#​77416)
  • remove direct ip/port bypass in dev origin check (#​77414)
  • switch development origin verification to be opt-in rather than opt-out (#​77395)
Credits

Huge thanks to@​ijjk and@​ztanner for helping!


Configuration

📅Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated byMend Renovate. View therepository job log.

@vercel
Copy link

vercelbot commentedApr 3, 2025
edited
Loading

The latest updates on your projects. Learn more aboutVercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
lyonjs-website✅ Ready (Inspect)Visit Preview💬Add feedbackJul 28, 2025 8:03pm

@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from2eea4bf tobd24b58CompareApril 15, 2025 09:20
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch frombd24b58 toaa875e2CompareApril 16, 2025 21:39
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch 2 times, most recently fromea30569 to35c3bbfCompareApril 16, 2025 21:43
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from35c3bbf to57c0758CompareApril 17, 2025 13:24
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from57c0758 to387f441CompareApril 17, 2025 14:55
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from387f441 toab3fb71CompareApril 19, 2025 13:58
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch fromab3fb71 to06cd23cCompareApril 24, 2025 06:45
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from06cd23c to1d4d80eCompareMay 27, 2025 11:57
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from1d4d80e to41db7ddCompareJune 3, 2025 22:31
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from41db7dd to9a41efdCompareJuly 28, 2025 19:47
@renovaterenovatebotforce-pushed therenovate/npm-next-vulnerability branch from9a41efd tof151448CompareJuly 28, 2025 19:50
@SlashgearSlashgear merged commit2a292bb intomasterJul 28, 2025
6 of 7 checks passed
@SlashgearSlashgear deleted the renovate/npm-next-vulnerability branchJuly 28, 2025 19:53
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@Slashgear

[8]ページ先頭

©2009-2025 Movatter.jp