Uh oh!
There was an error while loading. Please reload this page.
chore(deps): update dependency @sentry/nextjs to v7.77.0 [security] - #35
chore(deps): update dependency @sentry/nextjs to v7.77.0 [security]#35renovate[bot] wants to merge 1 commit into
Conversation
a35ecbf to
b371005CompareWarning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
b371005 to
a8eb5c8Comparea8eb5c8 to
75d0784Compare75d0784 to
fb1792cComparefb1792c to
62e4c1aCompare62e4c1a to
3f857a2Compare3f857a2 to
8d43809Compare8d43809 to
5388fedCompare5388fed to
4cc7ec3Compare4cc7ec3 to
6d8bcb9Compare6d8bcb9 to
c8eded0Comparec8eded0 to
2af5745Compare2af5745 to
6220bfeCompare6220bfe to
9828f1eCompare9828f1e to
555f438CompareReview the following changes in direct dependencies. Learn more about Socket for GitHub.
|
555f438 to
5598f78Compare5598f78 to
304b823Compare


This PR contains the following updates:
7.73.0→7.77.0Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint
CVE-2023-46729 / GHSA-2rmr-xw8m-22q9
More information
Details
Impact
An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This could open door for other attack vectors:
This issue only affects users who have Next.js SDK tunneling feature enabled.
Patches
The problem has been fixed in sentry/nextjs@7.77.0
Workarounds
Disable tunneling by removing the
tunnelRouteoption from Sentry Next.js SDK config —next.config.jsornext.config.mjs.References
Credits
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
getsentry/sentry-javascript (@sentry/nextjs)
v7.77.0Compare Source
Security Fixes
Other Changes
Bundle size 📦
v7.76.0Compare Source
Important Changes
This release adds
Sentry.withMonitor(), a wrapping function that wraps a callback with a cron monitor that will automatically report completions and failures:Other Changes
jsxandtsxfile extensions (#9362)replay_idis not added to DSC if session expired (#9359)Work in this release contributed by @LubomirIgonda1. Thank you for your contribution!
Bundle size 📦
v7.75.1Compare Source
Bundle size 📦
v7.75.0Compare Source
Important Changes
@sentry/opentelemetrypackage (#9238)This release publishes a new package,
@sentry/opentelemetry. This is a runtime agnostic replacement for@sentry/opentelemetry-nodeand exports a couple of useful utilities which can be used to use Sentry together with OpenTelemetry.You can read more about @sentry/opentelemetry in the Readme.
Starting with this release, you can configure the following build-time flags in order to reduce the SDK bundle size:
__RRWEB_EXCLUDE_CANVAS____RRWEB_EXCLUDE_IFRAME____RRWEB_EXCLUDE_SHADOW_DOM__You can read more about tree shaking in our docs.
Other Changes
lru_mapdependency (#9300)cookiemodule (#9308)ReplayandBrowserTracingintegrations tree-shakeable (#9287)autoInstrumentMiddlewarefunctionality (#9323)getInitialPropsmay return undefined (#9342)Bundle size 📦
v7.74.1Compare Source
astro-integrationkeyword (#9265)fetch(#9275)deferinjection logic. (#9242)Work in this release contributed by @LubomirIgonda1. Thank you for your contribution!
Bundle size 📦
v7.74.0Compare Source
Important Changes
sentryAstrointegration (#9218)This Release introduces the first alpha version of our new SDK for Astro.
At this time, the SDK is considered experimental and things might break and change in future versions.
The core of the SDK is an Astro integration which you easily add to your Astro config:
Check out the README for usage instructions and what to expect from this alpha release.
Other Changes
addIntegrationutility (#9186)continueTracemethod (#9164)VueIntegrationto initialize vue app later (#9180)referrerPolicyon serverside fetch transports (#9200)init(#9162)inspectorwhen needed (#9149)debugoption and instead add logger.isEnabled() (#9230).mjsand.cjsextensions from module name (#9231)processEventintegration hook (#9151)processEvent(#9021)rethrowAfterCaptureoption (#9159)walkmethod (#9157)Work in this release contributed by @aldenquimby. Thank you for your contributions!
Bundle size 📦
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.