Skip to content

Conversation

@ctate
Copy link

@ctate ctate commented Dec 11, 2025

This repository is listed on Vercel Templates.

This PR upgrades dependencies to patch a security vulnerability.

Action required

Please review the changes and run a quick test. If everything looks correct, you can merge this PR.
If you prefer to upgrade manually, feel free to close this and apply your own fix.

Thank you.


Note

Upgrade Next.js from 16.0.7 to 16.0.9 with corresponding lockfile updates.

  • Dependencies:
    • Bump next from 16.0.7 to 16.0.9 in package.json.
    • Update bun.lock entries for next, @next/env, and platform-specific @next/swc-* binaries to 16.0.9.

Written by Cursor Bugbot for commit 3097369. This will update automatically on new commits. Configure here.

This upgrade fixes CVE-2025-55182, a React Server Components RCE vulnerability.
@vercel
Copy link

vercel bot commented Dec 11, 2025

@ctate is attempting to deploy a commit to the kernel Team on Vercel.

A member of the Team first needs to authorize it.

@ICholding
Copy link

Commit

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants