fix(deps): update dependency next to v15.2.2 [security] #80
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR contains the following updates:
15.1.7→15.2.2GitHub Vulnerability Alerts
CVE-2025-48068
Summary
A low-severity vulnerability in Next.js has been fixed in version 15.2.2. This issue may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects local development environments and requires the user to visit a malicious webpage while
npm run devis active.Because the mitigation is potentially a breaking change for some development setups, to opt-in to the fix, you must configure
allowedDevOriginsin your next config after upgrading to a patched version. Learn more.Learn more: https://vercel.com/changelog/cve-2025-48068
Credit
Thanks to sapphi-red and Radman Siddiki for responsibly disclosing this issue.
CVE-2025-49826
Summary
A vulnerability affecting Next.js has been addressed. It impacted versions 15.0.4 through 15.1.8 and involved a cache poisoning bug leading to a Denial of Service (DoS) condition.
Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page
More details: CVE-2025-49826
Credits
Release Notes
vercel/next.js (next)
v15.2.2Compare Source
Core Changes
d55cc79b-20250228to443b7ff2-20250303: #76804443b7ff2-20250303toe03ac20f-20250305: #76842__next_app__module loading functions: #74566e03ac20f-20250305to029e8bd6-20250306: #76870xbutton present: #76898Example Changes
Misc Changes
redirectin client components: #76332labeler.json: #76828SyntaxContextfor__turbopack_esm__: #73544next.browserinstead ofwebdriverin pages/ client-navigation: #76867swc_coretov16.4.0: #76596v1.0.0-alpha.64: #76856__dirname: #76902Credits
Huge thanks to @pranathip, @gaojude, @ijjk, @eps1lon, @Nayeem-XTREME, @leerob, @styfle, @samcx, @sokra, @huozhi, @raunofreiberg, @mischnic, @lubieowoce, @unstubbable, @ztanner, @kdy1, @timneutkens, @wbinnssmith, @bgw, and @oscr for helping!
v15.2.1Compare Source
Core Changes
sourcePackagereferences: #76550revalidateproperty from incremental cachectxforFETCHkind: #76500cache-controlheader and prerender manifest: #762075.8.2: #76709generateStaticParams: #7671322e39ea7-20250225tod55cc79b-20250228: #76680Example Changes
paramscode blocks: #76705Misc Changes
swc_coretov16.0.0: #76414parallel-routes-revalidationtest: #76600octokit.rest.issues.addLabelscall: #76601devIndicatorsand note on deprecated options: #76611htmlLimitedBotsoption: #76616test-turbopack-integrationnot having any shards : #76355describeVariantshelper: #76631toDisplayRedbox(): replace all occurrences of testDir: #76618Credits
Huge thanks to @acdlite, @bgw, @ijjk, @molebox, @kdy1, @timneutkens, @devjiwonchoi, @mischnic, @unstubbable, @eps1lon, @huozhi, @philipithomas, @delbaoliveira, @samcx, @wbinnssmith, @sokra, @gnoff, @leerob, @ztanner, @raunofreiberg, @lubieowoce, and @LihaoWang for helping!
v15.2.0Compare Source
Core Changes
unstable_allowDynamicwhen used with pnpm: #73732.test.files from using error code plugin: #73868react-dev-overlaybefore fork: #74016GroupedStackFrames.tsx: #74028State<T>types into OperationValues and/or NonLocalValues: #74008react-dev-overlayfor new UI: #74017.stories.and.test.files from taskfile watch and error plugin: #740647283a213-20241206to372ec00c-20241209: #73749root-layout-missing-tags-error.tsxto pascal case: #74089bun.lockas package manager lockfile: #74056372ec00c-20241209to518d06d2-20241219: #74155images.qualitiesin next.config: #74257518d06d2-20241219to3b009b4c-20250102: #744923b009b4c-20250102to3ce77d55-20250106: #745573ce77d55-20250106to7b402084-20250107: #745997b402084-20250107to42687267-20250108: #7464942687267-20250108to74ea0c73-20250109: #7469374ea0c73-20250109to056073de-20250109: #74754056073de-20250109to540efebc-20250112: #74805540efebc-20250112tocabd8a0e-20250113: #74828"use cache"in metadata route handlers: #74835cabd8a0e-20250113tob3a95caf-20250113: #74868<Link prefetch={true}>: #74172CMD + .keyboard shortcut to show/hide: #74878b3a95caf-20250113tof0edf41e-20250115: #74890f0edf41e-20250115tob158439a-20250115: #74936b158439a-20250115to5b51a2b9-20250116: #74993waitUntil: #75041colorminfeature fromcssnano: #53393use cacheusage: #750075b51a2b9-20250116to9b62ee71-20250122: #75187afterexport in next-types-plugin: #75190linkheader from middleware with the ones from React: #73431"use cache": #74652"use cache"closures: #74750internal_disableSyncDynamicAPIWarningsflag: #75231Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
Version Bump
Please select the appropriate version bump by checking the corresponding box: