Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jun 15, 2025

This PR contains the following updates:

Package Change Age Confidence
next (source) 14.2.28 -> 14.2.30 age confidence

GitHub Vulnerability Alerts

CVE-2025-48068

Summary

A low-severity vulnerability in Next.js has been fixed in version 15.2.2. This issue may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects local development environments and requires the user to visit a malicious webpage while npm run dev is active.

Because the mitigation is potentially a breaking change for some development setups, to opt-in to the fix, you must configure allowedDevOrigins in your next config after upgrading to a patched version. Learn more.

Learn more: https://vercel.com/changelog/cve-2025-48068

Credit

Thanks to sapphi-red and Radman Siddiki for responsibly disclosing this issue.


Release Notes

vercel/next.js (next)

v14.2.30

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
Credits

Huge thanks to @​ijjk and @​ztanner for helping!

v14.2.29

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • Only share incremental cache for edge in next start (#​79389)
Credits

Huge thanks to @​ijjk for helping!


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the security label Jun 15, 2025
@renovate renovate bot added the security label Jun 15, 2025
@netlify
Copy link

netlify bot commented Jun 15, 2025

Deploy Preview for otelchangelog ready!

Name Link
🔨 Latest commit 2330203
🔍 Latest deploy log https://app.netlify.com/projects/otelchangelog/deploys/690d0d4653e6f5000857b184
😎 Deploy Preview https://deploy-preview-75--otelchangelog.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from a16ee8a to 4b00a61 Compare August 1, 2025 15:07
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch 2 times, most recently from 653cdb3 to 945a032 Compare August 13, 2025 14:33
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from 945a032 to 67fb85d Compare September 25, 2025 19:27
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from 67fb85d to 2330203 Compare November 6, 2025 21:04
@trask trask added this pull request to the merge queue Nov 6, 2025
Merged via the queue into main with commit e0f6442 Nov 6, 2025
7 checks passed
@trask trask deleted the renovate/npm-next-vulnerability branch November 6, 2025 21:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant