Skip to content

Fix React Server Components CVE vulnerabilities#112

Draft
malewis5 wants to merge 1 commit intoBlazity:mainfrom
malewis5:fix/cve-2025-66478
Draft

Fix React Server Components CVE vulnerabilities#112
malewis5 wants to merge 1 commit intoBlazity:mainfrom
malewis5:fix/cve-2025-66478

Conversation

@malewis5
Copy link
Copy Markdown

This PR upgrades dependencies to patch a security vulnerability.

Action required

Please review the changes and run a quick test. If everything looks correct, you can merge this PR. If you prefer to upgrade manually, feel free to close this and apply your own fix.

Thank you.

Updated dependencies to fix Next.js and React CVE vulnerabilities.

The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel
- react-server-dom-turbopack

All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.
@vercel
Copy link
Copy Markdown

vercel bot commented Dec 12, 2025

@malewis5 is attempting to deploy a commit to the Blazity Team on Vercel.

A member of the Team first needs to authorize it.

@vercel
Copy link
Copy Markdown

vercel bot commented Dec 16, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Review Updated (UTC)
hygraph-next-enterprise Ignored Ignored Dec 16, 2025 2:56pm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant