77.json (8412B)
1 { 2 "number": 77, 3 "title": "[Snyk] Security upgrade next from 12.0.10 to 12.1.0", 4 "state": "closed", 5 "diff_file": "77.diff", 6 "author": "snyk-bot", 7 "created_at": "2022-02-19T07:04:45Z", 8 "closed_at": "2022-02-19T13:38:55Z", 9 "merged_at": null, 10 "base_ref": "main", 11 "head_ref": "snyk-fix-ec56847e55b9142b31992e4669d02d24", 12 "labels": [], 13 "assignees": [], 14 "requested_reviewers": [], 15 "body": "<h3>Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.</h3>\n\n\n\n#### Changes included in this PR\n\n- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:\n - package.json\n - package-lock.json\n\n\n\n#### Vulnerabilities that will be fixed\n##### With an upgrade:\nSeverity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity\n:-------------------------:|-------------------------|:-------------------------|:-------------------------|:-------------------------\n | **581/1000** <br/> **Why?** Recently disclosed, Has a fix available, CVSS 5.9 | User Interface (UI) Misrepresentation of Critical Information <br/>[SNYK-JS-NEXT-2405694](https://snyk.io/vuln/SNYK-JS-NEXT-2405694) | No | No Known Exploit \n\n(*) Note that the real score may have changed since the PR was raised.\n\n\n\n\n\n<details>\n <summary><b>Commit messages</b></summary>\n </br>\n <details>\n <summary>Package name: <b>next</b></summary>\n The new version differs by 215 commits.</br>\n <ul>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/8545fd1bb02244ced9e8dc9584a764aeae296cd0\">8545fd1</a> v12.1.0</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/1605f3059c7773a346998da5e1de416d106d8f32\">1605f30</a> v12.0.11-canary.21</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/69aedbd6667753f02b76563598342c8afa646dfa\">69aedbd</a> Fix typo (#34480)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/f0f322c0d1655d722d133f963a84e575a61a5708\">f0f322c</a> Remove deprecation for relative URL usage in middlewares (#34461)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/d4d79b2d9b9c43ed1061a3d3beeb3099368669a8\">d4d79b2</a> Fix chunk buffering for server components (#34474)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/74fa4d4b93673a355d082473318562056571900f\">74fa4d4</a> update webpack (#34477)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/b70397e770a0badfbafe9e2db8cb8bfeb1b06f9e\">b70397e</a> Revert "Allow reading request bodies in middlewares (#34294)" (#34479)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/42020114d2ada652ed9651675ad62791743e432f\">4202011</a> Update font-optimization test snapshot (#34478)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/1edd8519d6626ac3972244253a14933185c76a33\">1edd851</a> Allow reading request bodies in middlewares (#34294)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/ba78437cfff866c02468b6b180f8ea72979ef76e\">ba78437</a> fix: don't wrap `profile` in firebase example (#34457)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/f3c3810addff3cf19d66f2cbb4b6ddb61d241aa1\">f3c3810</a> Remove hello world RSC example. (#34456)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/49da8c016cabd5c5b9703d66294db4be2dbce926\">49da8c0</a> v12.0.11-canary.20</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/2264d35b647461d78d6f64157eec8667a24f76fb\">2264d35</a> Fix `.svg` image optimization with a `loader` prop (#34452)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/59714db16deee949b426af3184f38ee243c89b8d\">59714db</a> Update server-only changes HMR handling (#34298)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/d288d43f19d9360e9676c638badc2ecd52649713\">d288d43</a> Update MDX Guide config example (#34405)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/54dbeb30c158d263c021e206fefc984035f8a208\">54dbeb3</a> update webpack (#34444)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/9b38ffe5d9d88a0c8e8837c022dd7203bed6da7e\">9b38ffe</a> Update 2.example_bug_report.yml</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/86aac3fa3d06beb8c339656cc7d13987607937ef\">86aac3f</a> Update 1.bug_report.yml</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/732b4052bda5d10b42ceaa87ba0067f74075971a\">732b405</a> v12.0.11-canary.19</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/01524ef20fe102d623bcde01e6b9d04e67e6f291\">01524ef</a> Revert swc css bump temporarily (#34440)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/8a55612c0d37d5b3fb6726eaa310aad01e0b42ab\">8a55612</a> Add image config for `dangerouslyAllowSVG` and `contentSecurityPolicy` (#34431)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/9639fe704cf5c4a5a477bdc0c43219514c811601\">9639fe7</a> Ensure we don't poll page in development when notFound: true is returned (#34352)</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/7e93a89ba05c70078647c6bb4dfd62372053fead\">7e93a89</a> Update 2.example_bug_report.yml</li>\n <li><a href=\"https://snyk.io/redirect/github/vercel/next.js/commit/d88793d973cb402dd877c855e7fea4ae7ff209a0\">d88793d</a> feat: improve opening a new issue flow (#34434)</li>\n </ul>\n\n <a href=\"https://snyk.io/redirect/github/vercel/next.js/compare/4c28177c15e7b90229e70d5030aa9a5b60918005...8545fd1bb02244ced9e8dc9584a764aeae296cd0\">See the full diff</a>\n </details>\n</details>\n\n\n\n\n\n\nCheck the changes in this PR to ensure they won't cause issues with your project.\n\n\n\n------------\n\n\n\n**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.*\n\nFor more information: <img src=\"https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0MDgxNDM3ZC01N2E4LTQ2NWItOGVmZC0zOTZiZTNmZTZmYzUiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjQwODE0MzdkLTU3YTgtNDY1Yi04ZWZkLTM5NmJlM2ZlNmZjNSJ9fQ==\" width=\"0\" height=\"0\"/><img src=\"https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=next&from_version=12.0.10&to_version=12.1.0&pr_id=4081437d-57a8-465b-8efd-396be3fe6fc5&visibility=false&has_feature_flag=false\" width=\"0\" height=\"0\"/>\n\ud83e\uddd0 [View latest project report](https://app.snyk.io/org/mtrnord/project/cfa462ee-5058-4b47-9a54-035933636a57?utm_source=github&utm_medium=referral&page=fix-pr)\n\n\ud83d\udee0 [Adjust project settings](https://app.snyk.io/org/mtrnord/project/cfa462ee-5058-4b47-9a54-035933636a57?utm_source=github&utm_medium=referral&page=fix-pr/settings)\n\n\ud83d\udcda [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities)\n\n[//]: # (snyk:metadata:{\"prId\":\"4081437d-57a8-465b-8efd-396be3fe6fc5\",\"prPublicId\":\"4081437d-57a8-465b-8efd-396be3fe6fc5\",\"dependencies\":[{\"name\":\"next\",\"from\":\"12.0.10\",\"to\":\"12.1.0\"}],\"packageManager\":\"npm\",\"projectPublicId\":\"cfa462ee-5058-4b47-9a54-035933636a57\",\"projectUrl\":\"https://app.snyk.io/org/mtrnord/project/cfa462ee-5058-4b47-9a54-035933636a57?utm_source=github&utm_medium=referral&page=fix-pr\",\"type\":\"auto\",\"patch\":[],\"vulns\":[\"SNYK-JS-NEXT-2405694\"],\"upgrade\":[\"SNYK-JS-NEXT-2405694\"],\"isBreakingChange\":false,\"env\":\"prod\",\"prType\":\"fix\",\"templateVariants\":[\"updated-fix-title\",\"priorityScore\",\"merge-advice-badge-shown\"],\"priorityScoreList\":[581]})\n", 16 "comments": [], 17 "review_comments": [] 18 }