fix(deps): patch HIGH/CRITICAL advisories #19

Merged
siax-bot merged 2 commits from fix/cve-lockfile-2026-09-30 into main 2026-10-01 15:52:11 +00:00
2 Commits
Author SHA1 Message Date
Claude CodeandClaude Sonnet 5.5 ddc4cce3eb fix(deps): next 16.3.3 -> 16.3.6 (GHSA-vcvr-r3jv-pc5j, CRITICAL)
masterplan-lock / check (pull_request) Successful in 9s
masterplan-lock / check (push) Successful in 35s
Remote code execution in next/og ImageResponse, fixed in 16.3.6.
Same minor line; the exact pin in package.json moves too and the
lockfile follows (next, @next/env, @next/swc-* platform binaries,
sharp optional range ^0.35.4).

Not fixed here (need a direct-dependency major bump or have no fix):
- nodemailer 9.1.1: GHSA-prgh-xp8r-p3m5 / GHSA-v53p-9fqp-m79j fixed only in 10.0.5/10.0.6 (major)
- xlsx 0.20.3: GHSA-4r6h-8v6p-xvw6 / GHSA-5pgg-2g8v-p4x9 have no published fix

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 18:50:50 +02:00
Claude CodeandClaude Sonnet 5.5 0250b4bab2 fix(deps): patch HIGH/CRITICAL advisories
masterplan-lock / check (push) Successful in 6s
masterplan-lock / check (pull_request) Successful in 33s
Lockfile-level update of the packages trivy flags on main, all within
their current major:

- next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL)
- js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375)
- nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj)
- sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c)
- undici 6.28.0 -> 6.29.0 (CVE-2026-19534)
- brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev)
- minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev)

next, js-yaml and nodemailer were exact-pinned, so their pins move too.
PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without
it the pinned-dep guard fails.

Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major
bump of a direct dependency, left for a separate reviewed change).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 17:17:51 +02:00