Skip to content

fix(deps): bump next to 16.3.8 for GHSA-vcvr-r3jv-pc5j and GHSA-2xp9-vwfh-vxw4 - #16

Merged
TrueLineCollective merged 1 commit into
mainfrom
fix/next-16.3.8
Oct 3, 2026
Merged

TrueLineCollective merged 1 commit into
mainfrom
fix/next-16.3.8

Conversation

@TrueLineCollective

Copy link
Copy Markdown
Owner

Why

Two critical Next.js advisories cover this repo's current version:

  • GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse. Affects >= 16.2.0, < 16.3.6. Patched in 16.3.6. Published 2026-09-30.
  • GHSA-2xp9-vwfh-vxw4: Unauthenticated Remote Code Execution in the Image Optimization API when AVIF files are used. Affects >= 16.0.0, < 16.3.3.

This PR moves to 16.3.8, the current npm latest, which clears both floors.

What changed

  • next 16.2.9 to 16.3.8 and eslint-config-next 16.2.9 to 16.3.8.
  • package-lock.json updated. Every lockfile change stays inside next's own dependency tree, all from registry.npmjs.org.
  • No source changes.

Checks

These ran locally on Node 22.23.3 and npm 10.9.9, to match the CI matrix:

Step Result
npm ci ok
installed next version 16.3.8, asserted >= 16.3.6
npm run typecheck clean
npm run lint clean
npm test 36 files, 255 tests passed
npm run build passed on Next.js 16.3.8

CI on this PR covers Node 20 and 22, plus the Docker build and boot smoke.

Generated with Claude Code (https://claude.com/claude-code)

next 16.2.9 is inside the affected range of:
- GHSA-vcvr-r3jv-pc5j: RCE in next/og ImageResponse (>=16.2.0 <16.3.6, patched 16.3.6)
- GHSA-2xp9-vwfh-vxw4: unauthenticated RCE in the Image Optimization API with AVIF (<16.3.3)

Bumps next and eslint-config-next to 16.3.8, the current npm latest. Dependency and lockfile change only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FdeA8nzAPvx92LuUuozKM7
@TrueLineCollective
TrueLineCollective merged commit 03155d2 into main Oct 3, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant