Skip to content

security: bump 19 package(s) in npm#5

Open
vtiwari-story wants to merge 1 commit into
mainfrom
depagent/sec-npm-20260520-174731
Open

security: bump 19 package(s) in npm#5
vtiwari-story wants to merge 1 commit into
mainfrom
depagent/sec-npm-20260520-174731

Conversation

@vtiwari-story
Copy link
Copy Markdown
Contributor

Security dependency upgrade

This PR was opened by depagent to address 19 security alert(s) in the npm ecosystem.

Each package is pinned to exactly the patched version reported by Dependabot's first_patched_version — not a range. To restore a range constraint (e.g. ^x.y.z), edit the manifest after merge.

Alerts addressed

Sev Package Vulnerable range Patched CVE GHSA EPSS KEV
high next >= 12.2.0, < 15.5.16 15.5.16 CVE-2026-44573 GHSA-36qx-fr4f-26g5 0.00 no
high next >= 12.2.0, < 15.5.16 15.5.16 CVE-2026-44573 GHSA-36qx-fr4f-26g5 0.00 no
high next >= 13.0.0, < 15.5.16 15.5.16 - GHSA-8h8q-6873-q5fj - no
high next >= 13.0.0, < 15.5.16 15.5.16 - GHSA-8h8q-6873-q5fj - no
high next >= 13.4.13, < 15.5.16 15.5.16 CVE-2026-44578 GHSA-c4j6-fc7j-m34r 0.04 no
high next >= 13.4.13, < 15.5.16 15.5.16 CVE-2026-44578 GHSA-c4j6-fc7j-m34r 0.04 no
high next >= 15.0.0, < 15.5.16 15.5.16 CVE-2026-44579 GHSA-mg66-mrh9-m8jx 0.00 no
high next >= 15.0.0, < 15.5.16 15.5.16 CVE-2026-44579 GHSA-mg66-mrh9-m8jx 0.00 no
high next >= 15.2.0, < 15.5.18 15.5.18 CVE-2026-45109 GHSA-26hh-7cqf-hhc6 0.00 no
high next >= 15.2.0, < 15.5.16 15.5.16 CVE-2026-44575 GHSA-267c-6grr-h53f 0.00 no
high next >= 15.2.0, < 15.5.16 15.5.16 CVE-2026-44575 GHSA-267c-6grr-h53f 0.00 no
high next >= 15.2.0, < 15.5.18 15.5.18 CVE-2026-45109 GHSA-26hh-7cqf-hhc6 0.00 no
high next >= 15.4.0, < 15.5.16 15.5.16 CVE-2026-44574 GHSA-492v-c6pp-mqqv 0.00 no
high next >= 15.4.0, < 15.5.16 15.5.16 CVE-2026-44574 GHSA-492v-c6pp-mqqv 0.00 no
high next >= 13.0.0, < 15.5.15 15.5.15 - GHSA-q4gf-8mx6-v5v3 - no
high next >= 13.0.0, < 15.5.15 15.5.15 - GHSA-q4gf-8mx6-v5v3 - no
high next >= 15.5.1-canary.0, < 15.5.10 15.5.10 - GHSA-h25m-26qc-wcjf - no
high next >= 15.5.1-canary.0, < 15.5.10 15.5.10 - GHSA-h25m-26qc-wcjf - no
high next >= 15.5.1-canary.0, < 15.5.8 15.5.8 - GHSA-mwv6-3258-q52c - no

Notes

  • Some changes are package overrides for transitive vulnerable deps (pnpm.overrides / overrides / resolutions). The vulnerable package isn't declared directly in the manifest — the override pins it to the patched version across the entire dependency graph for that workspace.
  • ⚠️ Lockfile NOT regenerated: npm failed: npm warn Unknown user config "audit-signatures". This will stop working in the next major version of npm.
    npm error code EOVERRIDE
    npm error Override for next@15.5.10 conflicts with direct dependency
    npm error A complete log of this run can be found in: /Users/securient/.npm/_logs/2026-05-20T17_47_31_735Z-debug-0.log. Please run your package manager's install locally and commit the lockfile update.

Generated by depagent — storyprotocol/react-quickstart.

@vtiwari-story vtiwari-story added security Created by depagent depagent Created by depagent labels May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

depagent Created by depagent security Created by depagent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant