Commit 1b21cc3
chore(deps): bump next to 15.5.19 for security patches
15.5.9 was behind on patch releases. 15.5.19 clears all 18 open GitHub
advisories for next (DoS, middleware/proxy bypass, SSRF CVE-2026-44578,
XSS, cache poisoning). None were exploitable in this static export
(output: "export" has no server runtime), and the React Server
Components RCE (CVE-2025-66478) was already fixed in 15.5.7 — but staying
on the latest 15.5.x patch removes the exposure entirely.
eslint-config-next aligned to 15.5.19 to match next.
Verified: production build, eslint (121 files, 0/0), pnpm audit reports
0 next advisories.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent bfa12e2 commit 1b21cc3
2 files changed
Lines changed: 69 additions & 90 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
33 | | - | |
| 33 | + | |
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
| 50 | + | |
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| |||
0 commit comments