Skip to content

Conversation

nerdy-tech-com-gitub
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade eslint-config-next from 13.1.6 to 15.5.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 1546 versions ahead of your current version.

  • The recommended version was released 22 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
140 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
140 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
140 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
140 Proof of Concept
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
140 No Known Exploit
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
140 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
140 Proof of Concept
Release notes
Package name: eslint-config-next
  • 15.5.0 - 2025-08-20

    Core Changes

    • Use and enforce exhaustive switch statements for work unit store: #81577
    • Enable @ typescript-eslint/switch-exhaustiveness-check rule: #81583
    • [dynamicIO] use RSC dynamicness to control partial vs complete PPR result: #81627
    • [dynamicIO] Do not use React.unstable_postpone(): #81652
    • feat: new detachable panel UI: #81483
    • Turbopack: content-hash PageLoaderAsset: #81450
    • [segment explorer] fix content overflow styling: #81649
    • Improve reliability of owner stacks for async I/O errors: #81501
    • fix(router): Prevent redirect loop on root data requests with basePath: #81096
    • Ensure custom NextServer config is honored: #81681
    • Fix before interactive incorrectly render css: #81146
    • perf: memorize exclude function in webpack config: #81525
    • Also enforce experimental features when there's no next config file: #81679
    • feat(next/image): warn when images.qualities is undefined: #81690
    • feat(build): optimize filterUniqueParamsCombinations to generate sub-combinations: #81321
    • Update NextAdapter type and re-export: #81692
    • upgrade to [email protected]: #80123
    • [metadata] replace for initial body icon case: #81688
    • [segment explorer] remove dev panel ui flag: #81670
    • Simplify running test apps locally with ppr or dynamicIO enabled: #81668
    • [turbopack] Return cached Promise from __turbopack_load_by_url__ : #81663
    • Upgrade React from 97cdd5d3-20250710 to 2f0e7e57-20250715: #81678
    • Delete unused renderToString function: #81707
    • Discard prerendered route handler data from FS cache after revalidation: #81611
    • Upgrade React from 2f0e7e57-20250715 to d85ec5f5-20250716: #81708
    • Ignore pending revalidations during prerendering: #81621
    • [turbopack] Clear chunk cache on HMR instead of creating new next-server VM: #81664
    • fix: rootParams should throw in client when fallbackParams are not present: #81711
    • perf(build): optimize buildAppStaticPaths performance and add helper function: #81386
    • Turbopack: Support string without options for @ next/mdx: #81713
    • [Segment Cache] Support dynamic head prefetching: #81677
    • [sourcemaps] Consistent cursor columns: #81375
    • fix: revert client segment route changes for sub shell generation: #81731
    • fix: pages router metadata bugs with React 19: #81733
    • Improve error handling for headers/cookies/draftMode in 'use cache': #81716
    • [devtool] fix duplicate rendered indicator on server: #81729
    • [devtool] enable segment explorer by default: #81737
    • [turbopack] Stop exposing globals from Turbopack runtime: #81727
    • Remove unnecessary await: #81761
    • [chore] bump zod to latest v3: #81757
    • feat(turbopack): Log anonymized internal error (panic) information to telemetry: #81272
    • fix: revert client segment route changes for sub shell generation: #81740
    • bugfix: static resources staleTime should be renewed once refetched: #81771
    • [devtool] move font styling to global.css: #81782
    • [devtool] copy decoded info of error details: #81735
    • fix(build): add sourcePage context for PPR dynamic route lambda creation: #81781
    • refactor: rename experimental.dynamicIO to experimental.cacheComponents: #81562
    • Properly handle hanging promise rejections during prerendering: #81754
    • Upgrade React from d85ec5f5-20250716 to dffacc7b-20250717: #81767
    • Refactor: Get rid of overly generic getExpectedRequestStore function: #81791
    • [devtool] migrate css reset to global.css: #81783
    • [dev-tools] Robust shortcut detection: #81756
    • [segment explorer] hide for pages router: #81813
    • [devtool] fix scrollbar styling: #81814
    • fix(ppr): ensure fallback route params trigger dynamic resume: #81812
    • [devtools] restart server pending state: #80858
    • Turbopack: fix dist dir on Windows: #81758
    • fix: remove boundary sentinel from RSC responses: #81857
    • [sourcemaps] Try VM for retrieving source maps first: #81869
    • [devtools] save user config inside .next/cache: #81807
    • Server: Remove unused code: #81886
    • refactor: encapsulate content type within RenderResult: #81861
    • refactor: handle null RenderResult responses gracefully: #81895
    • Upgrade React from dffacc7b-20250717 to e9638c33-20250721: #81899
    • chore(devtools): sync todos to linear: #81901
    • Introduce 'use cache: private': #81816
    • chore(deps): update browserslist: #81851
    • Remove web-server from edge-ssr-app: #81389
    • Stabilize node middleware support: #81907
    • Add run-turbopack-compiler trace span: #81917
    • fix: support calling onClose multiple times in edge-ssr-app: #81911
    • fix: logging the correct process for listened port: #81903
    • Build: Include rewrites in manifest generation: #81894
    • Routing: Clean up some code: #81932
    • [sourcemaps] Ensure codeframe when calling Client Functions from Server: #81918
    • [segment explorer] missing file suggestion: #81617
    • [turbopack] Always print trace labels in headers: #81728
    • Revert "[metadata] use https protocol for schema urls": #81934
    • Upgrade React from e9638c33-20250721 to 7513996f-20250722: #81940
    • Upgrade to swc v33: #81750
    • Remove extra base-server code: #81944
    • Turbopack: flatten sourceInfo to avoid objects, reorder args, compress node.js entry: #81545
    • Fix dynamicParams false layout case in dev: #81990
    • Initial MCP implementation: #81770
    • Fix: Unresolved param in x-nextjs-rewritten-query: #81991
    • Turbopack: Add an option to use system TLS certificates (fixes #79060, fixes #79059): #81818
    • Turbopack: Remove unused proxy option in turbo-tasks-fetch, lightly document HTTP_PROXY/HTTPS_PROXY environment variables: #81905
    • Upgrade React from 7513996f-20250722 to edac0dde-20250723: #81984
    • [devtools] Cleanup folder structure: #82012
    • [devtools] Fix "open in editor" for locations in stackframes: #82013
    • [Segment Cache] Fix: Key by rewritten search: #81986
    • Upgrade vercel og and remove yoga type patching: #81937
    • [perf] cache load config results: #80570
    • Turbopack: use prototype for turbopack context for better runtime performance: #81547
    • [reactcompiler] Test with latest RC: #82002
    • [devtools] Fix various exhaustive-deps violations: #82010
    • [devtools] Apply React Compiler to Next.js DevTools source: #82004
    • Upgrade React from edac0dde-20250723 to 3d14fcf0-20250724: #82020
    • Adjusted the warning message to be more descriptive: #82054
    • Track fallback params on workUnitStore: #82003
    • Fix API stripping JSON incorrectly: #82061
    • Upgrade React from 3d14fcf0-20250724 to 19baee81-20250725: #82063
    • use FetchStrategy to control prefetching behavior everywhere: #82032
    • [Segment Cache] set fetchStrategy on segments from a dynamic request: #82059
    • Revert "Upgrade vercel og and remove yoga type patching (#81937)": #82066
    • Optimize segment data routes: #82033
    • Turbopack: write tasks doesn't need to be session dependent, as effects will restore: #78727
    • [sourcemaps] Fully sourcemap stacks on the Server: #81904
    • fix(Rspack): use loaderContext.utils.contextify to replace ModuleFilenameHelpers.createFilename: #82104
    • next/root-params: #80255
    • fix(next/image): fix image-optimizer.ts headers: #82114
    • Upgrade React from 19baee81-20250725 to eaee5308-20250728: #82120
    • Fix validateRSCRequestHeaders incorrect redirect: #82119
    • fix(next/image): improve and simplify detect-content-type: #82118
    • [CacheComponents] Use fallback params when validating dynamic routes in dev: #82069
    • Extract getDynamicParam to a shared module: #82137
    • Fix i18n fallback: false collision: #82136
    • [segment explorer] normalize path when running inside monorepo: #82146
    • [segment explorer] windows compatibility: #82147
    • Upgrade React from eaee5308-20250728 to 9be531cd-20250729: #82159
    • Ensure setAssetPrefix updates config instance: #82160
    • Revert "Fix tracing of server actions imported by client components (#78968): #82161
    • Remove useMDXComponents argument: #80871
    • Fix RSC hash validation for middleware external rewrites: #82176
    • @ next/codemod: update docs url in README: #82135
    • @ next/codemod: Add experimental.turbo to turbopack codemod for Next.js configs: #82134
    • refactor: lowercase app router header values: #82169
    • Strip internals from NextRequest types: #82172
    • allow root params access in private caches: #82125
    • [devtool] bump base-ui to 1.0.0-beta.2: #82206
    • Upgrade @ vercel og: #82201
    • Upgrade React from 9be531cd-20250729 to 9784cb37-20250730: #82207
    • Fix: the unexpected clearing of symbolic link directories: #82191
    • [next-dev] Set TURBOPACK env before loading config: #82162
    • fix: display multiple lockfile warn if neither outputFileTracingRoot or turbopack.root option is provided: #82164
    • Revert "Initial MCP implementation (#81770)": #82217
    • Revert "Upgrade @ vercel og (#82201)": #82219
    • Fix: Don't bail out of prefetch if head is missing: #82216
    • Upgrade React from 9784cb37-20250730 to c260b38d-20250731: #82247
    • [Cache Components] Runtime prefetching: #81088
    • Parse dynamic params on the client:

Snyk has created this PR to upgrade eslint-config-next from 13.1.6 to 15.5.0.

See this package in npm:
eslint-config-next

See this project in Snyk:
https://app.snyk.io/org/nerds-github/project/cd0ad9f1-9f38-4860-92f7-d76da4843eb0?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants