Skip to content

Conversation

@vynride
Copy link

@vynride vynride commented Dec 15, 2025

This PR upgrades Next.js from 15.5.7 to 15.5.9 to address recently disclosed security vulnerabilities in the React Server Components (RSC) protocol.

Reference:

This update resolves the following vulnerabilities:

Note:

The current main branch fails to build due to an existing missing dependency @helenapankov/actionengine. This PR intentionally does not address that issue (even though adding the dependency fixes the build) in order to keep the scope strictly limited to the security upgrade.

I’m happy to open a separate PR or follow-up to address the build failure if needed.

@vynride
Copy link
Author

vynride commented Dec 24, 2025

@hpnkv Friendly bump in case this got buried, happy to adjust the PR if needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant