Skip to content

pnpm dependency update 2026-09-09 - #45

Merged
marco-commercelayer merged 1 commit into
mainfrom
chore/deps-update-202609091005
Sep 9, 2026
Merged

pnpm dependency update 2026-09-09#45
marco-commercelayer merged 1 commit into
mainfrom
chore/deps-update-202609091005

Conversation

@commercelayer-ci

Copy link
Copy Markdown
Contributor

Dependency update

Closes #44
Branch: chore/deps-update-202609091005
Based on stable: ``
Prerelease tag: skipped
Node.js: `24.x`
pnpm: `10.x`

Automated dependency update via pnpm. Review the dependency diff and validation output before merging.

Dependency update results

  • Check: success
  • Build: success
  • Test: success

Semver bump log

authentication/nextjs-auth0-sso/package.json
  @testing-library/dom  ^10.4.0  →  ^10.4.1
  concurrently           ^8.2.0  →   ^8.2.2
  cors                   ^2.8.5  →   ^2.8.6
  unstorage             ^1.17.1  →  ^1.17.5
  @auth0/nextjs-auth0              ^4.10.0  →   ^4.29.0
  @babel/core                      ^7.23.0  →   ^7.29.7
  @commercelayer/js-auth            ^7.0.0  →    ^7.4.2
  @commercelayer/react-components  ^4.26.1  →   ^4.29.7
  @commercelayer/sdk               ^6.47.0  →   ^6.58.0
  @testing-library/jest-dom         ^6.6.3  →   ^6.10.0
  @testing-library/react           ^16.2.0  →   ^16.3.3
  @vitejs/plugin-react              ^4.3.4  →    ^4.7.0
  auth0                             ^5.0.0  →   ^5.14.1
  dotenv                           ^16.0.3  →   ^16.6.1
  express                          ^4.18.2  →   ^4.22.2
  express-jwt                         ^8.0  →      ^8.5
  helmet                            ^7.1.0  →    ^7.2.0
  highlight.js                     ^11.9.0  →  ^11.12.0
  jwks-rsa                          ^3.1.0  →    ^3.2.2
  morgan                           ^1.10.0  →   ^1.12.0
  nodemon                           ^3.0.0  →   ^3.1.14
  prettier                          ^3.1.0  →    ^3.9.6
  reactstrap                        ^9.1.5  →    ^9.2.3
  start-server-and-test             ^2.0.0  →    ^2.1.5
  vitest                            ^3.0.9  →    ^3.2.7
  @fortawesome/react-fontawesome  ^0.2.2  →  ^0.2.6

cms/nextjs-contentful-store/package.json
  @types/js-cookie            ^3.0.1  →    ^3.0.6
  @types/node               ^17.0.19  →  ^17.0.45
  @types/prettier             ^2.7.2  →    ^2.7.3
  @types/styled-components   ^5.1.26  →   ^5.1.36
  contentful                  ^9.3.3  →    ^9.3.7
  contentful-import          ^8.5.61  →   ^8.5.63
  iframe-resizer-react        ^1.1.0  →    ^1.1.1
  js-cookie                   ^3.0.5  →    ^3.0.8
  query-string                ^7.1.1  →    ^7.1.3
  semantic-release           ^19.0.2  →   ^19.0.5
  styled-components           ^5.3.6  →   ^5.3.11
  tailwindcss                 ^3.4.7  →   ^3.4.19
  @commercelayer/js-auth       ^6.3.1  →    ^6.7.2
  @headlessui/react            ^1.5.0  →   ^1.7.19
  @next/eslint-plugin-next    ^13.1.6  →  ^13.5.11
  @types/lodash             ^4.14.195  →  ^4.17.25
  @types/react               ^18.0.28  →  ^18.3.31
  @types/react-dom           ^18.0.11  →   ^18.3.7
  dotenv                      ^16.3.1  →   ^16.6.1
  eslint                      ^8.34.0  →   ^8.57.1
  eslint-config-next          ^13.1.6  →  ^13.5.11
  eslint-config-prettier       ^8.6.0  →   ^8.10.2
  globby                      ^13.1.3  →   ^13.2.2
  next                        ^13.1.6  →  ^13.5.11
  postcss                     ^8.4.24  →   ^8.5.28
  postcss-preset-env           ^7.4.1  →    ^7.8.3
  prettier                     ^2.5.1  →    ^2.8.8
  react                       ^18.2.0  →   ^18.3.1
  react-dom                   ^18.2.0  →   ^18.3.1
  @tailwindcss/aspect-ratio   ^0.4.0  →   ^0.4.2
  @tailwindcss/forms          ^0.4.0  →   ^0.4.1
  @tailwindcss/typography     ^0.5.2  →  ^0.5.20
  axios                      ^0.26.0  →  ^0.26.1
  sharp                      ^0.32.1  →  ^0.32.6

solutions/commercelayer-slackbot/package.json
  @commercelayer/js-auth   ^4.1.1  →    ^4.3.0
  @commercelayer/sdk      ^4.25.0  →   ^4.57.0
  @slack/bolt             ^3.13.1  →   ^3.22.0
  @supabase/supabase-js   ^2.26.0  →  ^2.116.0
  dotenv                  ^16.0.3  →   ^16.6.1
  supabase                ^1.45.2  →  ^1.226.4
  tslib                    ^2.6.0  →    ^2.8.1

solutions/giftcard-tutorial/package.json
  @commercelayer/react-components  ^4.25.1  →  ^4.29.7
  @commercelayer/sdk               ^6.44.0  →  ^6.58.0
  react                            ^19.0.0  →  ^19.2.8
  react-dom                        ^19.0.0  →  ^19.2.8

solutions/js-sdk-sandbox/package.json
  parcel  ^2.12.0  →  ^2.16.4

solutions/pay-with-tweet/package.json
  @types/express  ^4.17.21  →  ^4.17.25
  nodemon           ^3.1.4  →   ^3.1.14
  @types/node  ^22.0.2  →  ^22.20.1
  dotenv       ^16.4.5  →   ^16.6.1
  express      ^4.19.2  →   ^4.22.2
  tsc-watch     ^6.2.0  →    ^6.3.1

webhooks/expressjs-signature-verification/package.json
  express  ^4.19.2  →  ^4.22.2

webhooks/sendgrid-templated-emails/package.json
  @sendgrid/mail  ^8.1.3  →  ^8.1.6
  dotenv   ^16.4.5  →  ^16.6.1
  express  ^4.19.2  →  ^4.22.2

webhooks/twilio-sms-notification/package.json
  dotenv   ^16.4.5  →  ^16.6.1
  express  ^4.19.2  →  ^4.22.2
  twilio    ^5.2.2  →  ^5.13.1

solutions/external-payment-gateway/packages/app/package.json
  @types/react      ^19.2.15  →  ^19.2.18
  @types/react-dom   ^19.2.3  →   ^19.2.7
  react              ^19.2.6  →   ^19.2.8
  react-dom          ^19.2.6  →   ^19.2.8
  @commercelayer/sdk    ^7.11.0  →  ^7.12.1
  @vitejs/plugin-react   ^6.0.2  →   ^6.1.1
  react-router-dom      ^7.15.1  →  ^7.18.3
  vite                  ^8.0.14  →   ^8.2.2

solutions/external-payment-gateway/packages/mollie-gateway/package.json
  @types/node  ^25.9.1  →  ^25.9.5
  @commercelayer/sdk   ^7.11.0  →   ^7.12.1
  @hono/node-server     ^2.0.4  →    ^2.1.1
  @mollie/api-client    ^4.5.0  →    ^4.6.0
  hono                ^4.12.22  →   ^4.13.7
  tsx                  ^4.15.6  →  ^4.23.13

Audit log

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ critical            │ Next.js: Unauthenticated Remote Code Execution on      │
│                     │ windows-hosted servers                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.0 <15.5.24                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=15.5.24                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-p293-qw3h-jr36      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ critical            │ Next.js: Unauthenticated Remote Code Execution in      │
│                     │ Image Optimization API when AVIF files are used        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <15.5.24                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=15.5.24                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-2xp9-vwfh-vxw4      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next.js Server-Side Request Forgery in Server Actions  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.0 <14.1.1                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=14.1.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-fr5h-rqp8-mj6g      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Server-Side Request Forgery in axios                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.3.2 <=1.7.3                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.7.4                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-8hc4-vh64-cxmj      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next.js authorization bypass vulnerability             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.5.5 <14.2.15                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=14.2.15                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-7gfc-8cq8-jh5f      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ axios Requests Vulnerable To Possible SSRF and         │
│                     │ Credential Leakage via Absolute URL                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <0.30.0                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=0.30.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>axios                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-jr5f-v2jv-69x6      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ axios Requests Vulnerable To Possible SSRF and         │
│                     │ Credential Leakage via Absolute URL                    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.8.2                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.8.2                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-jr5f-v2jv-69x6      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next Vulnerable to Denial of Service with Server       │
│                     │ Components                                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.3.0 <14.2.34                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=14.2.34                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-mwv6-3258-q52c      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next has a Denial of Service with Server Components -  │
│                     │ Incomplete Fix Follow-Up                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.3.1-canary.0 <14.2.35                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=14.2.35                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-5j59-xgg2-r9c4      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios is vulnerable to DoS attack through lack of data │
│                     │ size check                                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.12.0                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.12.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-4hjh-wcwx-xvwj      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next.js HTTP request deserialization can lead to DoS   │
│                     │ when using insecure React Server Components            │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.0.8                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=15.0.8                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-h25m-26qc-wcjf      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ minimatch has a ReDoS via repeated wildcards with      │
│                     │ non-matching literal in pattern                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ minimatch                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.6                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=9.0.6                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>eslint-config-next>@typescript-eslint/               │
│                     │ parser>@typescript-eslint/typescript-estree>minimatch  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-3ppc-4f35-3m26      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ minimatch has ReDoS: matchOne() combinatorial          │
│                     │ backtracking via multiple non-adjacent GLOBSTAR        │
│                     │ segments                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ minimatch                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.7                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=9.0.7                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>eslint-config-next>@typescript-eslint/               │
│                     │ parser>@typescript-eslint/typescript-estree>minimatch  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-7r86-cg39-jmmj      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ minimatch ReDoS: nested *() extglobs generate          │
│                     │ catastrophically backtracking regular expressions      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ minimatch                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.7                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=9.0.7                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>eslint-config-next>@typescript-eslint/               │
│                     │ parser>@typescript-eslint/typescript-estree>minimatch  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-23c5-xmqv-rm74      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next.js has a Denial of Service with Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.5.15                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=15.5.15                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-q4gf-8mx6-v5v3      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY    │
│                     │ Protection Bypassed via RFC 1122 Loopback Subnet       │
│                     │ (127.0.0.0/8) in Axios 1.15.0                          │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=0.31.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>axios                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-pmwg-cvhr-8vh7      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY    │
│                     │ Protection Bypassed via RFC 1122 Loopback Subnet       │
│                     │ (127.0.0.0/8) in Axios 1.15.0                          │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.15.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-pmwg-cvhr-8vh7      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios: Prototype Pollution Gadgets - Response          │
│                     │ Tampering, Data Exfiltration, and Request Hijacking    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=0.31.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>axios                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-pf86-5x62-jrwf      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios: Prototype Pollution Gadgets - Response          │
│                     │ Tampering, Data Exfiltration, and Request Hijacking    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.15.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-pf86-5x62-jrwf      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios: Header Injection via Prototype Pollution        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=0.31.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>axios                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-6chq-wfr3-2hj9      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios: Header Injection via Prototype Pollution        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1                                        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.15.1                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-6chq-wfr3-2hj9      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios is Vulnerable to Denial of Service via __proto__ │
│                     │ Key in mergeConfig                                     │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.30.2                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=0.30.3                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>axios                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-43fc-jf86-j433      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios is Vulnerable to Denial of Service via __proto__ │
│                     │ Key in mergeConfig                                     │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <=1.13.4                                       │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.13.5                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>@commercelayer/react-components>@commercelayer/      │
│                     │ sdk>axios                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-43fc-jf86-j433      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Next.js Vulnerable to Denial of Service with Server    │
│                     │ Components                                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ next                                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.5.16                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=15.5.16                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>next                                                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-8h8q-6873-q5fj      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Axios has prototype pollution read-side gadgets in     │
│                     │ HTTP adapter that allow credential injection and       │
│                     │ request hijacking                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ axios                                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.2                                        │
├─────────────────────┼───────────────────────────────────────��

...truncated...

@commercelayer-ci commercelayer-ci added the dependencies Pull requests that update a dependency file label Sep 9, 2026
@commercelayer-ci commercelayer-ci self-assigned this Sep 9, 2026
@marco-commercelayer
marco-commercelayer merged commit ce2cc9f into main Sep 9, 2026
1 check passed
@marco-commercelayer
marco-commercelayer deleted the chore/deps-update-202609091005 branch September 9, 2026 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pnpm dependency update 2026-09-09

2 participants