From a71e351fc6c07750b8dda11e6d087241242a6f21 Mon Sep 17 00:00:00 2001 From: Vercel Date: Thu, 11 Dec 2025 22:03:01 +0000 Subject: [PATCH] Fix React Server Components CVE vulnerabilities Updated dependencies to fix Next.js and React CVE vulnerabilities. The fix-react2shell-next tool automatically updated the following packages to their secure versions: - next - react-server-dom-webpack - react-server-dom-parcel - react-server-dom-turbopack All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory. Co-authored-by: Vercel --- apps/docs/package.json | 2 +- apps/marketing/package.json | 2 +- pnpm-lock.yaml | 80 ++++++++++++++++++------------------- 3 files changed, 42 insertions(+), 42 deletions(-) diff --git a/apps/docs/package.json b/apps/docs/package.json index fea2268..403c689 100644 --- a/apps/docs/package.json +++ b/apps/docs/package.json @@ -20,7 +20,7 @@ "clsx": "^2.1.1", "flags": "^3.2.0", "lucide-react": "^0.473.0", - "next": "15.1.9", + "next": "15.1.10", "react": "19.0.0", "react-dom": "19.0.0", "tailwind-merge": "^2.6.0", diff --git a/apps/marketing/package.json b/apps/marketing/package.json index d4b5c02..7714bf1 100644 --- a/apps/marketing/package.json +++ b/apps/marketing/package.json @@ -20,7 +20,7 @@ "clsx": "^2.1.1", "flags": "^3.2.0", "lucide-react": "^0.473.0", - "next": "15.1.9", + "next": "15.1.10", "react": "19.0.0", "react-dom": "19.0.0", "tailwind-merge": "^2.6.0", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index f3ebc9f..69df84c 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -37,16 +37,16 @@ importers: version: 1.2.3(@types/react@18.3.1)(react@19.0.0) '@vercel/analytics': specifier: ^1.5.0 - version: 1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + version: 1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) '@vercel/microfrontends': specifier: 1.2.4 - version: 1.2.4(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + version: 1.2.4(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) '@vercel/speed-insights': specifier: ^1.2.0 - version: 1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + version: 1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) '@vercel/toolbar': specifier: 0.1.36 - version: 0.1.36(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + version: 0.1.36(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) class-variance-authority: specifier: ^0.7.1 version: 0.7.1 @@ -55,13 +55,13 @@ importers: version: 2.1.1 flags: specifier: ^3.2.0 - version: 3.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + version: 3.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) lucide-react: specifier: ^0.473.0 version: 0.473.0(react@19.0.0) next: - specifier: 15.1.9 - version: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + specifier: 15.1.10 + version: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: specifier: 19.0.0 version: 19.0.0 @@ -110,16 +110,16 @@ importers: version: 1.2.3(@types/react@18.3.1)(react@19.0.0) '@vercel/analytics': specifier: ^1.5.0 - version: 1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + version: 1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) '@vercel/microfrontends': specifier: 1.2.4 - version: 1.2.4(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + version: 1.2.4(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) '@vercel/speed-insights': specifier: ^1.2.0 - version: 1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + version: 1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) '@vercel/toolbar': specifier: 0.1.36 - version: 0.1.36(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + version: 0.1.36(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) class-variance-authority: specifier: ^0.7.1 version: 0.7.1 @@ -128,13 +128,13 @@ importers: version: 2.1.1 flags: specifier: ^3.2.0 - version: 3.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + version: 3.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) lucide-react: specifier: ^0.473.0 version: 0.473.0(react@19.0.0) next: - specifier: 15.1.9 - version: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + specifier: 15.1.10 + version: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: specifier: 19.0.0 version: 19.0.0 @@ -645,12 +645,12 @@ packages: '@napi-rs/wasm-runtime@0.2.10': resolution: {integrity: sha512-bCsCyeZEwVErsGmyPNSzwfwFn4OdxBj0mmv6hOFucB/k81Ojdu68RbZdxYsRQUPc9l6SU5F/cG+bXgWs3oUgsQ==} + '@next/env@15.1.10': + resolution: {integrity: sha512-FA4AHiPh0RzXfQn1C7mp6G8KqREgiy+6mE06McrzeT8w1nYvmbLsxBAPZAg8gqDAk4XZKHC7siAkQc2TDRJzfg==} + '@next/env@15.1.6': resolution: {integrity: sha512-d9AFQVPEYNr+aqokIiPLNK/MTyt3DWa/dpKveiAaVccUadFbhFEvY6FXYX2LJO2Hv7PHnLBu2oWwB4uBuHjr/w==} - '@next/env@15.1.9': - resolution: {integrity: sha512-Te1wbiJ//I40T7UePOUG8QBwh+VVMCc0OTuqesOcD3849TVOVOyX4Hdrkx7wcpLpy/LOABIcGyLX5P/SzzXhFA==} - '@next/eslint-plugin-next@15.1.6': resolution: {integrity: sha512-+slMxhTgILUntZDGNgsKEYHUvpn72WP1YTlkmEhS51vnVd7S9jEEy0n9YAMcI21vUG4akTw9voWH02lrClt/yw==} @@ -2781,8 +2781,8 @@ packages: resolution: {integrity: sha512-myRT3DiWPHqho5PrJaIRyaMv2kgYf0mUVgBNOYMuCH5Ki1yEiQaf/ZJuQ62nvpc44wL5WDbTX7yGJi1Neevw8w==} engines: {node: '>= 0.6'} - next@15.1.9: - resolution: {integrity: sha512-OoQpDPV2i3o5Hnn46nz2x6fzdFxFO+JsU4ZES12z65/feMjPHKKHLDVQ2NuEvTaXTRisix/G5+6hyTkwK329kA==} + next@15.1.10: + resolution: {integrity: sha512-t+PruqHTsuSQZpl7H3hzxcJD5NR13JHfZU23z9QNEFC+g/z9QiAp52vykL5r1Tq3m0IrxnaXfjJSCMUAk6FDFQ==} engines: {node: ^18.18.0 || ^19.8.0 || >= 20.0.0} hasBin: true peerDependencies: @@ -4220,9 +4220,9 @@ snapshots: '@tybys/wasm-util': 0.9.0 optional: true - '@next/env@15.1.6': {} + '@next/env@15.1.10': {} - '@next/env@15.1.9': {} + '@next/env@15.1.6': {} '@next/eslint-plugin-next@15.1.6': dependencies: @@ -4665,12 +4665,12 @@ snapshots: '@unrs/resolver-binding-win32-x64-msvc@1.7.2': optional: true - '@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0)': + '@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0)': optionalDependencies: - next: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + next: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: 19.0.0 - '@vercel/microfrontends@1.1.0(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0)': + '@vercel/microfrontends@1.1.0(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0)': dependencies: ajv: 8.17.1 commander: 12.1.0 @@ -4681,15 +4681,15 @@ snapshots: nanoid: 3.3.11 path-to-regexp: 6.2.1 optionalDependencies: - '@vercel/analytics': 1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) - '@vercel/speed-insights': 1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) - next: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + '@vercel/analytics': 1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + '@vercel/speed-insights': 1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + next: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: 19.0.0 react-dom: 19.0.0(react@19.0.0) transitivePeerDependencies: - debug - '@vercel/microfrontends@1.2.4(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0)': + '@vercel/microfrontends@1.2.4(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0)': dependencies: '@next/env': 15.1.6 ajv: 8.17.1 @@ -4701,17 +4701,17 @@ snapshots: nanoid: 3.3.11 path-to-regexp: 6.2.1 optionalDependencies: - '@vercel/analytics': 1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) - '@vercel/speed-insights': 1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) - next: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + '@vercel/analytics': 1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + '@vercel/speed-insights': 1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0) + next: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: 19.0.0 react-dom: 19.0.0(react@19.0.0) transitivePeerDependencies: - debug - '@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0)': + '@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0)': optionalDependencies: - next: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + next: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: 19.0.0 '@vercel/style-guide@6.0.0(@next/eslint-plugin-next@15.1.6)(eslint@8.57.1)(jest@29.7.0)(prettier@3.5.3)(typescript@5.7.3)': @@ -4748,10 +4748,10 @@ snapshots: - supports-color - vitest - '@vercel/toolbar@0.1.36(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0)': + '@vercel/toolbar@0.1.36(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0)': dependencies: '@tinyhttp/app': 1.3.0 - '@vercel/microfrontends': 1.1.0(@vercel/analytics@1.5.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + '@vercel/microfrontends': 1.1.0(@vercel/analytics@1.5.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(@vercel/speed-insights@1.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react@19.0.0))(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0) chokidar: 3.6.0 execa: 5.1.1 fast-glob: 3.3.3 @@ -4760,7 +4760,7 @@ snapshots: jsonc-parser: 3.3.1 strip-ansi: 6.0.1 optionalDependencies: - next: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + next: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: 19.0.0 transitivePeerDependencies: - '@sveltejs/kit' @@ -5733,12 +5733,12 @@ snapshots: locate-path: 6.0.0 path-exists: 4.0.0 - flags@3.2.0(next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0): + flags@3.2.0(next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0))(react-dom@19.0.0(react@19.0.0))(react@19.0.0): dependencies: '@edge-runtime/cookies': 5.0.2 jose: 5.10.0 optionalDependencies: - next: 15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0) + next: 15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0) react: 19.0.0 react-dom: 19.0.0(react@19.0.0) @@ -6638,9 +6638,9 @@ snapshots: negotiator@0.6.4: {} - next@15.1.9(react-dom@19.0.0(react@19.0.0))(react@19.0.0): + next@15.1.10(react-dom@19.0.0(react@19.0.0))(react@19.0.0): dependencies: - '@next/env': 15.1.9 + '@next/env': 15.1.10 '@swc/counter': 0.1.3 '@swc/helpers': 0.5.15 busboy: 1.6.0