Production:
- next 16.3.4 -> 16.3.6 (apollo-docs, apollo-vertex): GHSA-vcvr-r3jv-pc5j
(critical, RCE in next/og ImageResponse)
- brace-expansion 5.0.9 -> 5.0.12 (surgical lockfile pin, no override):
GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr (moderate)
- js-yaml override >=5.4.1 (resolves 5.4.2): GHSA-r3ph-w7gj-g6xm (moderate)
- dompurify override >=3.4.16: GHSA-p98j-92pf-mc4p (low)
Dev:
- undici 7.29.0 -> 7.29.1 (via @semantic-release/github, ^7.0.0): GHSA-w293-vg96-wgc3,
GHSA-rfgv-xxqx-mfg5 (high) + 3wwx/pmjh/3xpg/2jfj/rx4f (moderate) + r53p/2gqq/8436 (low)
- undici 6.28.0 -> 6.28.1 (via @actions/http-client, ^6.23.0): GHSA-rfgv-xxqx-mfg5 (high),
GHSA-3wwx-pv8p-q78v (moderate), GHSA-r53p-7pc4-xj5r (low)
- ip-address 10.3.1 -> 10.7.2 (via express-rate-limit, ^10.2.0): GHSA-rpw4-54j3-4h4q,
GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw (moderate)
- fast-uri override ^3.1.6 -> ^3.1.8 (resolves 3.1.8): GHSA-qw65-cvwx-89v3,
GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj (moderate)
Version-scoped quarantine exemptions for next@16.3.6 and dompurify@3.4.16
(both < 14 days); all other versions > 14 days old. undici, ip-address and
brace-expansion use the surgical pin; parent ranges hold the patched
versions. All vetted 2026-09-30: publisher unchanged, tag + diff match
advisories, no new deps, lockfile integrity matches registry. Lockfile also
dedupes @swc/helpers 0.5.19->0.5.23 and one semver 7.7.4->7.8.5 onto
versions already locked.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
Clears
pnpm audit --prod(was 1 critical, 2 high, 2 moderate, 1 low) and the dev-dependency advisories that were in #1259, which is folded in here.Production
nextnext/ogImageResponse)apollo-docsandapollo-vertexbrace-expansionoverrides:unchangedjs-yaml>=5.4.1dompurify>=3.4.16next@16.3.6anddompurify@3.4.16are under 14 days old, so both have version-scopedminimumReleaseAgeExcludeentries. The@next/*comment is bumped to 16.3.6.Dev
undici7.x@semantic-release/githubuses^7.0.0undici6.x@actions/http-clientuses^6.23.0ip-addressexpress-rate-limituses^10.2.0fast-uri^3.1.8A surgical pin means adding a temporary override, installing, removing the override and installing again ("Already up to date"). The resulting
overrides:block differs only in thefast-uriline. All versions are older than 14 days, so no quarantine exemptions are needed.Supply-chain vetting (2026-09-30)
v16.3.6by eps1lon cites the advisory; the fix commit is868fad3"Harden next/og SVG serialization" and the rest are 16.3.x backports. Deps unchanged apart from@next/env.src/index.tsand tests. Deps unchanged.forceQuotesfix (docs(apollo-vertex): add intro to Adding a New Component #798). Deps unchanged.src/purify.ts+62/-5 adds the_handleHookDetachedNodechecks the advisory describes. The build moved from rollup to rolldown, which is whydist/churns. No new runtime deps.index.jsandlib/utils.js, with tests. No dependencies.isGlobal,offset/nextNetwork, IANA classifiers). All 26 commits are by the maintainer, including the 4 fork-merge GHSA fixes; 10.7.2 only adds afromArpafix. No dependencies.integrityfor each package matchesnpm view.Lockfile scope
Outside the eight target packages, the only changes are pnpm dedupes onto versions already in the lockfile:
@swc/helpers0.5.19 → 0.5.23 (rspack peer) and onesemver7.7.4 → 7.8.5 (make-dir). No new packages.Test plan
pnpm audit --prod: no known vulnerabilitiespnpm check:dependencies: passesNot in this PR
A new moderate advisory for
hono(<4.13.7,hono/jsxunescaped strings) was published after this work started. It still fails the fullpnpm auditand will follow separately.🤖 Generated with Claude Code