77.md (7998B)
1 # PR #77 [Snyk] Security upgrade next from 12.0.10 to 12.1.0 2 3 - **Status:** closed 4 - **Author:** @snyk-bot 5 - **Created:** 2022-02-19T07:04:45Z 6 - **Branch:** snyk-fix-ec56847e55b9142b31992e4669d02d24 → main 7 - **Closed:** 2022-02-19T13:38:55Z 8 - **Diff:** [77.diff](./77.diff) 9 10 --- 11 12 <h3>Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.</h3> 13 14 15 16 #### Changes included in this PR 17 18 - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: 19 - package.json 20 - package-lock.json 21 22 23 24 #### Vulnerabilities that will be fixed 25 ##### With an upgrade: 26 Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity 27 :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- 28  | **581/1000** <br/> **Why?** Recently disclosed, Has a fix available, CVSS 5.9 | User Interface (UI) Misrepresentation of Critical Information <br/>[SNYK-JS-NEXT-2405694](https://snyk.io/vuln/SNYK-JS-NEXT-2405694) | No | No Known Exploit 29 30 (*) Note that the real score may have changed since the PR was raised. 31 32 33 34 35 36 <details> 37 <summary><b>Commit messages</b></summary> 38 </br> 39 <details> 40 <summary>Package name: <b>next</b></summary> 41 The new version differs by 215 commits.</br> 42 <ul> 43 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/8545fd1bb02244ced9e8dc9584a764aeae296cd0">8545fd1</a> v12.1.0</li> 44 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/1605f3059c7773a346998da5e1de416d106d8f32">1605f30</a> v12.0.11-canary.21</li> 45 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/69aedbd6667753f02b76563598342c8afa646dfa">69aedbd</a> Fix typo (#34480)</li> 46 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/f0f322c0d1655d722d133f963a84e575a61a5708">f0f322c</a> Remove deprecation for relative URL usage in middlewares (#34461)</li> 47 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/d4d79b2d9b9c43ed1061a3d3beeb3099368669a8">d4d79b2</a> Fix chunk buffering for server components (#34474)</li> 48 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/74fa4d4b93673a355d082473318562056571900f">74fa4d4</a> update webpack (#34477)</li> 49 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/b70397e770a0badfbafe9e2db8cb8bfeb1b06f9e">b70397e</a> Revert "Allow reading request bodies in middlewares (#34294)" (#34479)</li> 50 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/42020114d2ada652ed9651675ad62791743e432f">4202011</a> Update font-optimization test snapshot (#34478)</li> 51 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/1edd8519d6626ac3972244253a14933185c76a33">1edd851</a> Allow reading request bodies in middlewares (#34294)</li> 52 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/ba78437cfff866c02468b6b180f8ea72979ef76e">ba78437</a> fix: don't wrap `profile` in firebase example (#34457)</li> 53 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/f3c3810addff3cf19d66f2cbb4b6ddb61d241aa1">f3c3810</a> Remove hello world RSC example. (#34456)</li> 54 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/49da8c016cabd5c5b9703d66294db4be2dbce926">49da8c0</a> v12.0.11-canary.20</li> 55 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/2264d35b647461d78d6f64157eec8667a24f76fb">2264d35</a> Fix `.svg` image optimization with a `loader` prop (#34452)</li> 56 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/59714db16deee949b426af3184f38ee243c89b8d">59714db</a> Update server-only changes HMR handling (#34298)</li> 57 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/d288d43f19d9360e9676c638badc2ecd52649713">d288d43</a> Update MDX Guide config example (#34405)</li> 58 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/54dbeb30c158d263c021e206fefc984035f8a208">54dbeb3</a> update webpack (#34444)</li> 59 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/9b38ffe5d9d88a0c8e8837c022dd7203bed6da7e">9b38ffe</a> Update 2.example_bug_report.yml</li> 60 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/86aac3fa3d06beb8c339656cc7d13987607937ef">86aac3f</a> Update 1.bug_report.yml</li> 61 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/732b4052bda5d10b42ceaa87ba0067f74075971a">732b405</a> v12.0.11-canary.19</li> 62 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/01524ef20fe102d623bcde01e6b9d04e67e6f291">01524ef</a> Revert swc css bump temporarily (#34440)</li> 63 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/8a55612c0d37d5b3fb6726eaa310aad01e0b42ab">8a55612</a> Add image config for `dangerouslyAllowSVG` and `contentSecurityPolicy` (#34431)</li> 64 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/9639fe704cf5c4a5a477bdc0c43219514c811601">9639fe7</a> Ensure we don't poll page in development when notFound: true is returned (#34352)</li> 65 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/7e93a89ba05c70078647c6bb4dfd62372053fead">7e93a89</a> Update 2.example_bug_report.yml</li> 66 <li><a href="https://snyk.io/redirect/github/vercel/next.js/commit/d88793d973cb402dd877c855e7fea4ae7ff209a0">d88793d</a> feat: improve opening a new issue flow (#34434)</li> 67 </ul> 68 69 <a href="https://snyk.io/redirect/github/vercel/next.js/compare/4c28177c15e7b90229e70d5030aa9a5b60918005...8545fd1bb02244ced9e8dc9584a764aeae296cd0">See the full diff</a> 70 </details> 71 </details> 72 73 74 75 76 77 78 Check the changes in this PR to ensure they won't cause issues with your project. 79 80 81 82 ------------ 83 84 85 86 **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* 87 88 For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0MDgxNDM3ZC01N2E4LTQ2NWItOGVmZC0zOTZiZTNmZTZmYzUiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjQwODE0MzdkLTU3YTgtNDY1Yi04ZWZkLTM5NmJlM2ZlNmZjNSJ9fQ==" width="0" height="0"/><img src="https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=next&from_version=12.0.10&to_version=12.1.0&pr_id=4081437d-57a8-465b-8efd-396be3fe6fc5&visibility=false&has_feature_flag=false" width="0" height="0"/> 89 🧐 [View latest project report](https://app.snyk.io/org/mtrnord/project/cfa462ee-5058-4b47-9a54-035933636a57?utm_source=github&utm_medium=referral&page=fix-pr) 90 91 🛠 [Adjust project settings](https://app.snyk.io/org/mtrnord/project/cfa462ee-5058-4b47-9a54-035933636a57?utm_source=github&utm_medium=referral&page=fix-pr/settings) 92 93 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) 94 95 [//]: # (snyk:metadata:{"prId":"4081437d-57a8-465b-8efd-396be3fe6fc5","prPublicId":"4081437d-57a8-465b-8efd-396be3fe6fc5","dependencies":[{"name":"next","from":"12.0.10","to":"12.1.0"}],"packageManager":"npm","projectPublicId":"cfa462ee-5058-4b47-9a54-035933636a57","projectUrl":"https://app.snyk.io/org/mtrnord/project/cfa462ee-5058-4b47-9a54-035933636a57?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-NEXT-2405694"],"upgrade":["SNYK-JS-NEXT-2405694"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore","merge-advice-badge-shown"],"priorityScoreList":[581]}) 96 97