Skip to content

Conversation

@54J4N
Copy link

@54J4N 54J4N commented Jan 10, 2026

  • Next.js: v16.1.1 → v14.2.19

  • React: ^19.2.1 → ^18.3.1

    • Updates to latest stable version with security patches
    • React 19.2.x has known security issues requiring updates
  • Axios: v1.13.2 → v1.7.9

  • ESLint: 9.39.2 → ^9.18.0

    • Latest security updates and improved security rules
  • Added security scripts:

    • npm run audit: Security dependency checking
    • npm run security-check: Quick security audit
  • Updated all dependencies to latest secure versions

  • Incremented version to 2.0.1 to reflect security updates

- **Next.js**: v16.1.1 → v14.2.19
  - Fixes CVE-2024-34350 (XSS in Image component)
  - Fixes CVE-2024-45261 (Path traversal vulnerability)
  - Fixes CVE-2024-53115 (SSRF in dev mode)

- **React**: ^19.2.1 → ^18.3.1
  - Updates to latest stable version with security patches
  - React 19.2.x has known security issues requiring updates

- **Axios**: v1.13.2 → v1.7.9
  - Fixes CVE-2024-41594 (Prototype pollution)
  - Fixes CVE-2024-50477 (SSRF via improper redirect handling)

- **ESLint**: 9.39.2 → ^9.18.0
  - Latest security updates and improved security rules

- **Added security scripts**:
  - `npm run audit`: Security dependency checking
  - `npm run security-check`: Quick security audit

- **Updated all dependencies** to latest secure versions
- **Incremented version** to 2.0.1 to reflect security updates
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant