Skip to content

Conversation

@sumansaurabh
Copy link
Contributor

@sumansaurabh sumansaurabh commented Apr 18, 2025

User description

snyk-top-banner

Snyk has created this PR to upgrade @next/third-parties from 14.2.11 to 14.2.26.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 15 versions ahead of your current version.

  • The recommended version was released 24 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
315 No Known Exploit
critical severity Improper Authorization
SNYK-JS-NEXT-9508709
315 Mature
Release notes
Package name: @next/third-parties
  • 14.2.26 - 2025-03-24

    Note

    This release is backporting bug fixes. It does not include all pending features/changes on canary.

    Core Changes

    • Match subrequest handling for edge and node (#77476)
  • 14.2.25 - 2025-03-17
  • 14.2.24 - 2025-02-11
  • 14.2.23 - 2025-01-07
  • 14.2.22 - 2024-12-26
  • 14.2.21 - 2024-12-19
  • 14.2.20 - 2024-12-04
  • 14.2.19 - 2024-12-03
  • 14.2.18 - 2024-11-13
  • 14.2.17 - 2024-11-05
  • 14.2.16 - 2024-10-23
  • 14.2.15 - 2024-10-08
  • 14.2.14 - 2024-10-01
  • 14.2.13 - 2024-09-20
  • 14.2.12 - 2024-09-17
  • 14.2.11 - 2024-09-12
from @next/third-parties GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • Snyk has automatically assigned this pull request, set who gets assigned.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:


Description

  • Upgraded @next/third-parties from version 14.2.5 to 14.2.26 to improve security and functionality.
  • This upgrade addresses vulnerabilities related to improper input validation and authorization.

Changes walkthrough 📝

Relevant files
Dependencies
package.json
Upgrade @next/third-parties Dependency Version                     

package.json

  • Upgraded @next/third-parties dependency version from 14.2.5 to
    14.2.26.
  • +1/-1     

    💡 Penify usage:
    Comment /help on the PR to get a list of all available Penify tools and their descriptions

    Snyk has created this PR to upgrade @next/third-parties from 14.2.11 to 14.2.26.
    
    See this package in npm:
    @next/third-parties
    
    See this project in Snyk:
    https://app.snyk.io/org/sumansaurabh/project/569040e7-a26f-4ef9-a26e-4c16b49d3e71?utm_source=github&utm_medium=referral&page=upgrade-pr
    @sumansaurabh sumansaurabh self-assigned this Apr 18, 2025
    @penify-dev penify-dev bot added enhancement New feature or request Review effort [1-5]: 1 labels Apr 18, 2025
    @penify-dev
    Copy link
    Contributor

    penify-dev bot commented Apr 18, 2025

    PR Review 🔍

    ⏱️ Estimated effort to review [1-5]

    1, because this is a straightforward dependency upgrade with no complex changes.

    🧪 Relevant tests

    No

    ⚡ Possible issues

    No

    🔒 Security concerns

    No

    @penify-dev
    Copy link
    Contributor

    penify-dev bot commented Apr 18, 2025

    PR Code Suggestions ✨

    CategorySuggestion                                                                                                                                    Score
    Compatibility
    Verify compatibility of the upgraded dependency with the existing codebase

    Ensure that the upgrade to version 14.2.26 of @next/third-parties is compatible with your
    existing codebase and other dependencies to avoid potential issues.

    package.json [15]

    -"@next/third-parties": "^14.2.26",
    +"@next/third-parties": "^14.2.26", // Ensure compatibility
     
    Suggestion importance[1-10]: 5

    Why: While ensuring compatibility is important, the suggestion does not provide a concrete code change and is more of a general recommendation. The comment proposed in 'improved_code' is also not added in the actual code diff.

    5

    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    3 participants