Skip to content

security: vulnerability remediation - #127

Open
kernel-internal[bot] wants to merge 1 commit into
mainfrom
security/vuln-remediation
Open

security: vulnerability remediation#127
kernel-internal[bot] wants to merge 1 commit into
mainfrom
security/vuln-remediation

Conversation

@kernel-internal

@kernel-internalkernel-internalBot commented Jul 29, 2026

Copy link
Copy Markdown

Vulnerability Remediation

This PR was generated by the Socket-centric vulnerability remediation workflow. Review the planned dependency changes and confirmation evidence before merging.

Fixed

CVE/GHSAPackageEcosystemOld VersionNew VersionManifestConfirmation
GHSA-4633-3j49-mh5qnextNone16.2.616.2.11confirmed

Not Included

  • Deferred by batch limit: 69 advisories. They will be considered by future runs.
  • Other deferred scanner findings: 311.
  • Unconfirmed attempted fixes: 0.
Deferred details
CVE/GHSAPackageReason
Unavailable from detectorsharp-libvips-darwin-arm64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-darwin-x64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linux-armNon-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linux-arm64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linux-ppc64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linux-riscv64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linux-s390xNon-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linux-x64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linuxmusl-arm64Non-CVE alert is not handled by dependency remediation.
Unavailable from detectorsharp-libvips-linuxmusl-x64Non-CVE alert is not handled by dependency remediation.
......301 additional items omitted from PR body. See workflow artifacts for full details.

Note

Medium Risk
Next.js underpins routing, SSR, and MCP/API handlers for the whole app; even patch releases can affect request handling, but scope is limited to a vendor security fix with no custom code changes.

Overview
Bumps Next.js from 16.2.6 to 16.2.11 in package.json and refreshes bun.lock so resolved next, @next/env, and platform @next/swc-* packages align with the patched release.

This is a patch-level security remediation for advisory GHSA-4633-3j49-mh5q; there are no application source changes.

Reviewed by Cursor Bugbot for commit bab8eca. Bugbot is set up for automated code reviews on this repo. Configure here.

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
mcpReadyReadyPreviewAug 19, 2026 3:24am

@socket-security

socket-securityBot commented Jul 29, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednext@​16.2.6 ⏵ 16.2.1164100+4090+19970

View full report

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit ca7ccd8. Configure here.

Comment threadbun.lock Outdated

@ulziibay-kernelulziibay-kernel left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified the bump against the advisory's first patched version; rebuilt on current main and confirmed the toolchain lock/build is clean. CI green.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ulziibay-kernel