[Snyk] Security upgrade next from 9.5.5 to 10.0.2 - #171
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-TAR-17909068 - https://snyk.io/vuln/SNYK-JS-TAR-17909152
|
The upgrade from Next.js v9 to v10 introduces several new features and a key behavioral change that requires verification. While the official documentation states there are no breaking changes, routing is now case-sensitive by default. Developers should verify that the casing used in Key New Features:
Recommendation: The primary action required is to audit internal links to ensure they use case-sensitive paths. While this is a minor version bump to Source: Next.js 10 Release Notes, Upgrading to Version 10 Guide
|
⛔ Snyk checks have failed. 15 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
There was a problem hiding this comment.
Orca Security Scan Summary
| Status | Check | Issues by priority | |
|---|---|---|---|
| Infrastructure as Code | View in Orca | ||
| OSS Licenses | View in Orca | ||
| SAST | View in Orca | ||
| Secrets | View in Orca | ||
| Vulnerabilities | View in Orca |
☢️ The following Vulnerabilities (CVEs) have been detected
| PACKAGE | FILE | CVE ID | INSTALLED VERSION | FIXED VERSION | ||
|---|---|---|---|---|---|---|
| ini | ./package-lock.json | CVE-2020-7788 | 1.3.5 | 1.3.6 | View in code | |
| next | ./package-lock.json | CVE-2021-39178 | 10.0.2 | 11.1.1 | View in code | |
| next | ./package-lock.json | CVE-2026-44577 | 10.0.2 | 15.5.16, 16.2.5 | View in code | |
| sharp | ./package-lock.json | GHSA-54xq-cgqr-rpm3 | 0.26.2 | 0.32.6 | View in code | |
| simple-get | ./package-lock.json | CVE-2022-0355 | 3.1.0 | 4.0.1, 3.1.1, 2.8.2 | View in code | |
| tar-fs | ./package-lock.json | CVE-2024-12905 | 2.1.0 | 1.16.4, 2.1.2, 3.0.7 | View in code | |
| tar-fs | ./package-lock.json | CVE-2025-48387 | 2.1.0 | 1.16.5, 2.1.3, 3.0.9 | View in code | |
| tar-fs | ./package-lock.json | CVE-2025-59343 | 2.1.0 | 3.1.1, 2.1.4, 1.16.6 | View in code |
Note: The scan should have failed if no policies were configured in warn-only mode.
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-TAR-17909068
SNYK-JS-TAR-17909152
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling