Skip to content

deps(deps): bump recharts from 3.5.1 to 3.7.0 in /frontend - #162

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/recharts-3.7.0
Open

deps(deps): bump recharts from 3.5.1 to 3.7.0 in /frontend#162
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/recharts-3.7.0

deps(deps): bump recharts from 3.5.1 to 3.7.0 in /frontend

183b1b1
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Feb 2, 2026 in 3s

6 new alerts including 1 critical severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 critical
  • 2 high
  • 3 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 8671 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

next: React Server Components: Pre-authentication remote code execution via unsafe deserialization Critical

Package: next
Installed Version: 16.0.5
Vulnerability CVE-2025-55182
Severity: CRITICAL
Fixed Version: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7
Link: CVE-2025-55182

Check failure on line 8671 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next Vulnerable to Denial of Service with Server Components High

Package: next
Installed Version: 16.0.5
Vulnerability GHSA-mwv6-3258-q52c
Severity: HIGH
Fixed Version: 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17
Link: GHSA-mwv6-3258-q52c

Check failure on line 8671 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components High

Package: next
Installed Version: 16.0.5
Vulnerability GHSA-h25m-26qc-wcjf
Severity: HIGH
Fixed Version: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5
Link: GHSA-h25m-26qc-wcjf

Check warning on line 8671 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Next Server Actions Source Code Exposure Medium

Package: next
Installed Version: 16.0.5
Vulnerability GHSA-w37m-7fhw-fmv9
Severity: MEDIUM
Fixed Version: 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17
Link: GHSA-w37m-7fhw-fmv9

Check warning on line 8671 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

next: NextJS Denial of Service in Image Optimizer Medium

Package: next
Installed Version: 16.0.5
Vulnerability CVE-2025-59471
Severity: MEDIUM
Fixed Version: 15.5.10, 16.1.5
Link: CVE-2025-59471

Check warning on line 8671 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

next: NextJS Denial of Service in Partial Pre Rendering Medium

Package: next
Installed Version: 16.0.5
Vulnerability CVE-2025-59472
Severity: MEDIUM
Fixed Version: 16.1.5, 15.6.0-canary.61
Link: CVE-2025-59472