Repository navigation
fix(security): patch Next.js ImageResponse advisory floor - #1805
seonghobae wants to merge 2 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-head admission correction — Ready is review admission only. Fresh audit against base
This PR is moved to Draft/Proposed until the causal owner repair is present on a successor exact head and re-audited. Queued/pending work is neither an additional blocker nor passing evidence. No Close, force push, destructive rebase, manual rerun, synthetic status/approval, merge, auto-merge, or bypass was performed. |
Scope
Stacked follow-up to #1798 at
8b8d6a6d0bf73b0b4e2fc19e65709284a211e40b; the owner branch is preserved.The primary advisory GHSA-vcvr-r3jv-pc5j affects Next.js >=16.2.0,<16.3.6. Pin Next.js and its ESLint config to 16.3.6 and regenerate the existing pnpm lock. No current next/og/ImageResponse usage was found; exploitability is not established.
Verification
No security exclusions or protected merge settings change.