Skip to content

Bump next from 15.5.19 to 15.5.21 in the npm_and_yarn group across 1 directory - #37

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-5988e9b934
Open

Bump next from 15.5.19 to 15.5.21 in the npm_and_yarn group across 1 directory#37
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-5988e9b934

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the / directory: next.

Updates next from 15.5.19 to 15.5.21

Release notes

Sourced from next's releases.

v15.5.21

This release contains security fixes for the following advisories:

High:

Moderate:

v15.5.20

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 15.5.15.

Commits
  • e26f6ff v15.5.21
  • 7f5deeb [15.x] Improve performance of checking valid MPA form submissions
  • 57c31f7 [15.x] Enforce serverActions.bodySizeLimit for Server Actions in Edge runtime
  • e3e5666 [15.x] Set correct origin for internal redirects in custom server
  • 35f5013 [15.x] Ensure exotic rewrite param values are properly encoded
  • 062f667 [15.x] fix(fetch-cache): key fetch(Request, init) by the effective request
  • 577c9dc [15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies
  • 530d4fa [15.x] fix(next/image): improve performance of detectContentType()
  • 8fabaf3 [15.x] Performance improvements when decoding React Server function payloads
  • ff12a61 [15.x] Validate server reference IDs during manifest lookup
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Summary by cubic

Upgrade next to 15.5.21 to address multiple high/moderate security advisories (DoS, SSRF, middleware bypass) and small performance improvements in caching and image optimization. Only dependency files were updated (package.json and lockfiles); no app code changes required.

Written for commit 0b35a65. Summary will update on new commits.

Review in cubic

Bumps the npm_and_yarn group with 1 update in the / directory: [next](https://github.com/vercel/next.js).


Updates `next` from 15.5.19 to 15.5.21
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v15.5.19...v15.5.21)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 15.5.21
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 28, 2026
@codesherlock-ai

Copy link
Copy Markdown

We could not run your PR Review. We noticed that you are part of an Org. We require everyone who is part of an Org to SignUp via GitHub so we can track your individual usage and maximize on your usage capacity. Enroll into CodeSherlock system by signing up via GitHub using the SignUp link. Also, please note — every user pays for their own usage.

@semanticdiff-com

semanticdiff-com Bot commented Jul 28, 2026

Copy link
Copy Markdown

Review changes with  SemanticDiff

Changed Files
File Status
  pnpm-lock.yaml  41% smaller
  package.json  0% smaller
  yarn.lock Unsupported file format

@cr-gpt

cr-gpt Bot commented Jul 28, 2026

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@netlify

netlify Bot commented Jul 28, 2026

Copy link
Copy Markdown

Deploy Preview for larme failed.

Name Link
🔨 Latest commit 0b35a65
🔍 Latest deploy log https://app.netlify.com/projects/larme/deploys/6a688cdcc479860007d4a756

@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
airmerge Ready Ready Preview, Comment Jul 28, 2026 11:06am

@codeant-ai

codeant-ai Bot commented Jul 28, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@codereviewbot-ai

Copy link
Copy Markdown

🤖 Review skipped: reviews for bot-created pull requests are not allowed on free accounts. Upgrade to a paid plan to enable bot reviews.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 28, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
airmerge 0b35a65 Jul 28 2026, 11:05 AM

@difflens

difflens Bot commented Jul 28, 2026

Copy link
Copy Markdown

View changes in DiffLens

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​15.5.19 ⏵ 15.5.2152100 +3191 +19970

View full report

@what-the-diff

what-the-diff Bot commented Jul 28, 2026

Copy link
Copy Markdown

PR Summary

  • Updated "next" package
    The "next" package, a crucial part of our codebase, has been updated from version 15.0.0 to 15.5.21. This brings us a series of improvements and bug fixes provided by this new version. The update is reflected in the package.json file and pnpm-lock.yaml.

  • Updated "@emnapi/runtime" package
    We've updated the "@emnapi/runtime" package in the pnpm-lock.yaml file from the previous version 1.11.1 to the new version 1.11.3. This package update will provide us with the latest functionality, performance improvements, and bug fixes.

  • Updated 'caniuse-lite' package
    Our 'caniuse-lite' package, which we use to ensure that our code is universally compatible, has been updated. The new version is 1.0.30001806, updated from 1.0.30001799.

  • Updated nanoid package
    We have updated the 'nanoid' package from 3.3.14 to 3.3.16. This is a small package that helps with generating unique identifiers and has been updated to its latest version for optimal performance.

  • Added libc specification
    We have added 'libc' specifications for several packages in the pnpm-lock.yaml. These specifications will help us better regulate how these packages interact with the system's core libraries.

@difflens

difflens Bot commented Jul 28, 2026

Copy link
Copy Markdown

View changes in DiffLens

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@llamapreview llamapreview Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LlamaPReview — Verification needed

Whether the Workers Builds: airmerge failure (check_run:the cited check) is caused by the Next.js 15.5.21 version bump or is a pre-existing issue.

Owner action: Inspect the Cloudflare Workers build logs at https://dash.cloudflare.com/6b3ac940a05caf6f636ded39a36f3b1c/workers/services/view/airmerge/production/builds/a96a6e4a-e76d-4b7e-b645-8687d7c15d96 and compare with a build on the base branch.

1 further check in details.

Review details and evidence
Priority File Finding Evidence
P2 package.json Next.js 15.5.21 includes behavioral security fixes; application compatibility with affected features is unverified needs verification

Finding details

P2 · Next.js 15.5.21 includes behavioral security fixes; application compatibility with affected features is unverified

package.json

The PR updates Next.js from 15.5.19 to 15.5.21. The release notes describe security fixes that alter runtime behavior for: Server Actions (enforced body size limits in Edge runtime and replay protection), rewrites (SSRF fix via destination hostname validation), middleware (bypass fix for single-locale App Router), custom servers (correct internal redirect origin), fetch caching (key construction for requests with bodies and non-UTF-8 payloads), and image optimization (SVG DoS fix). Repository searches for use server, middleware, and explicit fetch cache directives returned no hits on the default branch, but the application's source code and next.config.js were not retrieved. If the application uses any affected feature, the update could silently alter behavior. Maintainers should confirm the application does not depend on the patched behaviors, or verify through integration testing that affected features continue to work with 15.5.21.

Verification boundary: needs verification; scope: changed region.

Material unknowns

  • The application uses one or more Next.js features affected by the 15.5.21 security fixes (Server Actions, rewrites with dynamic hostnames, middleware with single locale, custom servers, fetch caching with request bodies, or image optimization with SVGs).
    • Check: Inspect application source code and next.config.js for usage of these features, or run integration tests against the PR branch.
  • Whether the Workers Builds: airmerge failure (check_run:the cited check) is caused by the Next.js 15.5.21 version bump or is a pre-existing issue.
  • Whether the Netlify deploy preview failures (Redirect rules, Header rules, Pages changed - all for larme) are caused by the Next.js 15.5.21 version bump or are pre-existing.

LlamaPReview checks

  • Reviewed changed regions in package.json.
  • Reviewed changed regions in pnpm-lock.yaml.
  • Reviewed changed regions in yarn.lock.

Automated review by LlamaPReview · Free for public open-source projects.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code size/L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants