Skip to content
Discussion options

You must be logged in to vote

This is a valid and important security concern. The user is requesting an upgrade of the @babel/runtime package bundled inside next/dist/compiled from version 7.22.5 to 7.26.10 in Next.js version 14.2.30, since 7.22.5 has known vulnerabilities flagged by security scanners (e.g., GHSA-968p-4wvh-cqc8).

Suggested response for a maintainer or community support:
Thank you for raising this security issue regarding the bundled version of @babel/runtime in Next.js 14.2.30. We understand that the current version (7.22.5) has known vulnerabilities and that upgrading to 7.26.10 would mitigate these risks.

Next Steps:

The Next.js team typically reviews dependency upgrades regularly and prioritizes se…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by joohyung-lee
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
2 participants