Skip to content

fix(deps): update dependency next to v14.2.30 [security] #171

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Jun 15, 2025

This PR contains the following updates:

Package Change Age Confidence
next (source) 14.2.21 -> 14.2.30 age confidence

GitHub Vulnerability Alerts

CVE-2025-48068

Summary

A low-severity vulnerability in Next.js has been fixed in version 15.2.2. This issue may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects local development environments and requires the user to visit a malicious webpage while npm run dev is active.

Because the mitigation is potentially a breaking change for some development setups, to opt-in to the fix, you must configure allowedDevOrigins in your next config after upgrading to a patched version. Learn more.

Learn more: https://vercel.com/changelog/cve-2025-48068

Credit

Thanks to sapphi-red and Radman Siddiki for responsibly disclosing this issue.


Release Notes

vercel/next.js (next)

v14.2.30

Compare Source

v14.2.29

Compare Source

v14.2.28

Compare Source

v14.2.27

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • fix dynamic route interception not working when deployed with middleware (#​64923)
Credits

Huge thanks to @​ztanner for helping!

v14.2.26

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • Match subrequest handling for edge and node (#​77476)

v14.2.25

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.
This release contains a security patch for CVE-2025-29927.

Core Changes
  • Update middleware request header (#​77202)
Credits

Huge thanks to @​ijjk for helping!

v14.2.24

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
Credits

Huge thanks to @​ztanner for helping!

v14.2.23

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • backport: force module format for virtual client-proxy (#​74590)
  • Backport: Use provided waitUntil for pending revalidates (#​74573)
  • Feature: next/image: add support for images.qualities in next.config (#​74500)
Credits

Huge thanks to @​styfle, @​ijjk and @​lubieowoce for helping!

v14.2.22

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • Retry manifest file loading only in dev mode: #​73900
  • Ensure workers are cleaned up: #​71564
  • Use shared worker for lint & typecheck steps: #​74154
Credits

Huge thanks to @​unstubbable, @​ijjk, and @​ztanner for helping!


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions github-actions bot added the type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. label Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from f80b58f to 52c96e9 Compare June 15, 2025 03:29
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 52c96e9 to eaf515c Compare June 15, 2025 06:47
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from eaf515c to f67cd21 Compare June 15, 2025 11:43
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from f67cd21 to f69c6ee Compare June 15, 2025 14:59
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from f69c6ee to f913c7d Compare June 15, 2025 19:34
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from f913c7d to 90e1cbc Compare June 15, 2025 23:30
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 90e1cbc to 48f0993 Compare June 16, 2025 04:26
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jun 16, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 48f0993 to b15572d Compare June 16, 2025 15:58
@github-actions github-actions bot removed the type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. label Jun 16, 2025
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 14, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 6c943f7 to 072b4ff Compare July 14, 2025 14:40
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 14, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 072b4ff to f870998 Compare July 14, 2025 21:53
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 14, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from f870998 to fbd461b Compare July 15, 2025 05:00
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from fbd461b to 7214085 Compare July 15, 2025 16:07
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 7214085 to cb6c8a0 Compare July 15, 2025 21:35
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 15, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from cb6c8a0 to 55c83a4 Compare July 16, 2025 05:06
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 16, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 55c83a4 to 01c2678 Compare July 16, 2025 15:54
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 16, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 01c2678 to 9433d5a Compare July 16, 2025 21:38
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 16, 2025
@renovate-bot renovate-bot force-pushed the renovate/npm-next-vulnerability branch from 9433d5a to cccccd9 Compare July 17, 2025 04:46
@github-actions github-actions bot added type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. and removed type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant