Title: Bump next from 16.2.3 to 16.2.6 by dependabot[bot] · Pull Request #91 · github-samples/gitfolio · GitHub
Open Graph Title: Bump next from 16.2.3 to 16.2.6 by dependabot[bot] · Pull Request #91 · github-samples/gitfolio
X Title: Bump next from 16.2.3 to 16.2.6 by dependabot[bot] · Pull Request #91 · github-samples/gitfolio
Description: Bumps next from 16.2.3 to 16.2.6.
Release notes
Sourced from next's releases.
v16.2.6
[!NOTE]
This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.
Security Fixes
The following advisories have been addressed:
High:
GHSA-8h8q-6873-q5fj: Denial of Service with Server Components
GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
GHSA-26hh-7cqf-hhc6: Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
GHSA-mg66-mrh9-m8jx: Denial of Service via connection exhaustion in applications using Cache Components
GHSA-492v-c6pp-mqqv: Middleware / Proxy bypass through dynamic route parameter injection
GHSA-c4j6-fc7j-m34r: Server-side request forgery in applications using WebSocket upgrades
GHSA-36qx-fr4f-26g5: Middleware / Proxy bypass in Pages Router applications using i18n
Moderate:
GHSA-ffhc-5mcf-pf4q: Cross-site scripting in App Router applications using CSP nonces
GHSA-gx5p-jg67-6x7h: Cross-site scripting in beforeInteractive scripts with untrusted input
GHSA-h64f-5h5j-jqjh: Denial of Service in the Image Optimization API
GHSA-wfc6-r584-vfw7: Cache poisoning in React Server Component responses
Low:
GHSA-vfv6-92ff-j949: Cache poisoning via collisions in React Server Component cache-busting
GHSA-3g8h-86w9-wvmq: Middleware / Proxy redirects can be cache-poisoned
Core Changes
fix: preserve HTTP access fallbacks during prerender recovery (#92231)
Fix fallback route params case in app-page handler (#91737)
Fix invalid HTML response for route-level RSC requests in deployment adapter (#91541)
Patch setHeader for direct route handlers (#93101)
Include deployment id in cacheHandlers keys (#93453)
Fix double-encoding of URL pathname parts in client param parsing (#93491)
v16.2.5
[!NOTE]
This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.
Security Fixes
The following advisories have been addressed:
High:
GHSA-8h8q-6873-q5fj: Denial of Service with Server Components
GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
GHSA-mg66-mrh9-m8jx: Denial of Service via connection exhaustion in applications using Cache Components
GHSA-492v-c6pp-mqqv: Middleware / Proxy bypass through dynamic route parameter injection
GHSA-c4j6-fc7j-m34r: Server-side request forgery in applications using WebSocket upgrades
... (truncated)
Commits
ee6e79b v16.2.6
afa053d Turbopack: Match proxy matchers with webpack implementation (#93594)
97a154e Turbopack: Fix middleware matcher suffix (#93590)
83899bc [backport] Disable build caches for production/staging/force-preview deploys ...
7b222b9 [backport][test] Pin package manager to patch versions (#93595)
a8dc24f [backport] Turbopack: more strict vergen setup (#93587)
766148f v16.2.5
0dd9483 fix: add explicit checks for RSC header (#83) (#98)
d166096 fix proxy matching for segment prefetch URLs (#89) (#96)
9d50c0b Strip next-resume header from incoming requests (#92)
Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show
Open Graph Description: Bumps next from 16.2.3 to 16.2.6. Release notes Sourced from next's releases. v16.2.6 [!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending f...
X Description: Bumps next from 16.2.3 to 16.2.6. Release notes Sourced from next's releases. v16.2.6 [!NOTE] This release contains security fixes and backported bug fixes. It does not include all pendi...
Opengraph URL: https://github.com/github-samples/gitfolio/pull/91
X: @github
Domain: www.github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:29eaaccc-f07f-60fe-5929-2e2ea570d4de |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | B8F8:1ABD8E:57EC1AF:754E963:6A5DD0A3 |
| html-safe-nonce | a1f0063ce15ae85351e748c22bf74d3cf3c9ec07d8d053c3b9740a892700196b |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCOEY4OjFBQkQ4RTo1N0VDMUFGOjc1NEU5NjM6NkE1REQwQTMiLCJ2aXNpdG9yX2lkIjoiMTI4NDc0OTI3NDA2OTcxNzE1NSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 9de91cc1cdd9d687165f12a94623c0dd888df57a19c26e55ce4bb789b32ebb60 |
| hovercard-subject-tag | pull_request:3672281621 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/github-samples/gitfolio/pull/91/files |
| twitter:image | https://avatars.githubusercontent.com/in/29110?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/in/29110?s=400&v=4 |
| og:image:alt | Bumps next from 16.2.3 to 16.2.6. Release notes Sourced from next's releases. v16.2.6 [!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending f... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5290d7e14309ad1e76106a9c4237bd1041517e83ea182c8ab756752cb0c6940b |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/github-samples/gitfolio git https://github.com/github-samples/gitfolio.git |
| octolytics-dimension-user_id | 190547141 |
| octolytics-dimension-user_login | github-samples |
| octolytics-dimension-repository_id | 1129823629 |
| octolytics-dimension-repository_nwo | github-samples/gitfolio |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1129823629 |
| octolytics-dimension-repository_network_root_nwo | github-samples/gitfolio |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 9c975978430e9ad293956f2bbdaf153b1bd84a99 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width