Repository navigation
fix(deps): patch Next.js og RCE, clear audit findings, update dependencies - #212
Merged
Merged
Conversation
- Upgrade Next.js and eslint-config-next to 16.3.8 (critical RCE in next/og ImageResponse, used by the site, blog, docs and portfolio OG routes; also image-optimizer SSRF and cache-poisoning fixes) - Upgrade nodemailer to 10.0.14 (no patched 9.x); drop @types/nodemailer, v10 ships its own types - Upgrade express to 4.22.3 (qs 6.16), multer to 2.4.0, vitest to 4.1.11 - Raise postcss to 8.5.28 (nanoid 3.3.19) - Fix overrides that pinned vulnerable versions: fast-uri 3.1.8, body-parser 1.20.8; the old fast-uri pin never applied to the locked tree - Override mysql2 3.24.5 and deepmerge-ts 8.0.2, both pinned vulnerable by prisma 7.x - Refresh brace-expansion, qs, @xmldom/xmldom and nanoid within range npm audit: 21 (1 critical, 14 high, 6 moderate) -> 5 high, all one lint-only chain (braces via @next/eslint-plugin-next) with no upstream fix.
- Prisma 7.10.0 (prisma, @prisma/client, @prisma/config, @prisma/adapter-pg) - Hold better-auth and @better-auth/prisma-adapter at ~1.6.25: 1.7 needs a mandatory Account.issuer column and backfill - server: @aws-sdk 3.1146, dodopayments 2.52, mammoth 1.13, pg 8.23, resend 6.32, compression 1.8.2, uuid 14.0.2, tsx 4.23.15 - studio: @react-pdf/renderer 4.9, docx 9.8.1, playwright 1.63 - lucide-react 1.51, libphonenumber-js 1.13.14, sonner 2.0.8, zustand 5.0.15, tailwind-merge 3.7, prettier 3.9.9 - site: declare tsx, used by its prebuild scripts but previously only reachable through server's hoisted copy Not changed: fumadocs-* (pinned by overrides; newer mdx/openapi need fumadocs-core ^16.15) and all breaking majors (zod 4, eslint 10, TS 7, express 5, vitest 5, redis 6, openai 7, helmet 8, framer-motion 14).
…rrides - Pin fumadocs-core/ui 16.13.0 and fumadocs-mdx 15.2.0 exactly in both blog-platform and docs-platform (and fumadocs-openapi 11.2.2 in docs), matching the installed versions - Keep the root fumadocs-core/ui overrides: they force a single copy for fumadocs-mdx, fumadocs-openapi and @fumadocs/api-docs, which declare their own ranges - Remove nested fumadocs and @hono/node-server entries that repeated top-level overrides - Remove overrides for hono, @hono/node-server and better-sqlite3 (no longer in the dependency tree) and for valibot (@prisma/dev already pins 1.4.2) - veriworkly.md: Next.js 16.3.8, and correct the Playwright claim (it is a Studio dev dependency for browser tests, not used by any export path) Installed dependency tree is unchanged.
- Bump version to 3.25.1 across root, site, studio, portfolio, blog-platform, docs-platform and server, plus the Studio and portfolio build labels - Add release notes and the v3.25.1 changelog seed entry - Local setup guide and README: npm 11 or higher is required
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
npm auditreported 21 vulnerabilities, including a critical RCE innext/ogImageResponse, which the site, blog, docs and portfolio OG image routes all use. This PR fixes everything with an upstream fix, updates dependencies within their current majors, and cleans up the rootoverrides.The 5 remaining findings are one chain,
braces←micromatch←fast-glob@3.3.1←@next/eslint-plugin-next. It is only used by lint, never shipped, and has no patched version yet.Commits
1.
fix(deps): securitycreateTransport/sendMailusage is unchanged.@types/nodemaileris removed because v10 ships its own types.fast-uri3.1.8 (the old 3.1.7 pin had never applied to the locked tree) andbody-parser1.20.8mysql23.24.5 anddeepmerge-ts8.0.2, both pinned vulnerable inside prisma 7.x2.
chore(deps): updates within current majors~1.6.25: 1.7 requires a mandatoryAccount.issuercolumn and a backfill, so it needs its own migration PRtsx. Its prebuild scripts use it, but it previously only worked through server's hoisted copy.3.
chore(deps): fumadocs pinning and override cleanuphono,@hono/node-server,better-sqlite3), a no-op (valibot) and nested duplicates of top-level rules. The installed tree is unchanged.4.
chore(release): 3.25.1release-notes-v3.25.1.md) and the changelog seed entryNot changed (separate PRs)
Breaking majors (zod 4, eslint 10, TypeScript 7, express 5, vitest 5, redis 6, openai 7, helmet 8, framer-motion 14), better-auth 1.7, and fumadocs 16.15+. The newer fumadocs-mdx and fumadocs-openapi require it, so it has to move as one coordinated upgrade.
Verification
Run on the original tree first as a baseline, then after each commit:
npm ci --legacy-peer-deps(same as CI), Prisma generate/validate, lint, formatnpm run buildfor all 8 workspaces/api/ogon the site and portfolio production builds returns valid PNGs on 16.3.8, and nodemailer 10 composes a message with our exact transport options and fieldsNotes for local setup
packageManager: npm@11.16.0). npm 10.9 crashes resolvingeslint-config-next@16.3.8peers.npm cifrom the lockfile works on both.test:browser) neednpx playwright install chromiumafter the Playwright 1.63 bump.