Dependency update tracking
Date: 2026-09-09
Branch: chore/deps-update-202609091005
Prerelease tag: skipped
Node.js: 24.x
pnpm: 10.x
This issue tracks the automated dependency update. It will be closed automatically when the linked PR is merged.
Dependency update results
- Check: success
- Build: success
- Test: success
Semver bump log
authentication/nextjs-auth0-sso/package.json
@testing-library/dom ^10.4.0 → ^10.4.1
concurrently ^8.2.0 → ^8.2.2
cors ^2.8.5 → ^2.8.6
unstorage ^1.17.1 → ^1.17.5
@auth0/nextjs-auth0 ^4.10.0 → ^4.29.0
@babel/core ^7.23.0 → ^7.29.7
@commercelayer/js-auth ^7.0.0 → ^7.4.2
@commercelayer/react-components ^4.26.1 → ^4.29.7
@commercelayer/sdk ^6.47.0 → ^6.58.0
@testing-library/jest-dom ^6.6.3 → ^6.10.0
@testing-library/react ^16.2.0 → ^16.3.3
@vitejs/plugin-react ^4.3.4 → ^4.7.0
auth0 ^5.0.0 → ^5.14.1
dotenv ^16.0.3 → ^16.6.1
express ^4.18.2 → ^4.22.2
express-jwt ^8.0 → ^8.5
helmet ^7.1.0 → ^7.2.0
highlight.js ^11.9.0 → ^11.12.0
jwks-rsa ^3.1.0 → ^3.2.2
morgan ^1.10.0 → ^1.12.0
nodemon ^3.0.0 → ^3.1.14
prettier ^3.1.0 → ^3.9.6
reactstrap ^9.1.5 → ^9.2.3
start-server-and-test ^2.0.0 → ^2.1.5
vitest ^3.0.9 → ^3.2.7
@fortawesome/react-fontawesome ^0.2.2 → ^0.2.6
cms/nextjs-contentful-store/package.json
@types/js-cookie ^3.0.1 → ^3.0.6
@types/node ^17.0.19 → ^17.0.45
@types/prettier ^2.7.2 → ^2.7.3
@types/styled-components ^5.1.26 → ^5.1.36
contentful ^9.3.3 → ^9.3.7
contentful-import ^8.5.61 → ^8.5.63
iframe-resizer-react ^1.1.0 → ^1.1.1
js-cookie ^3.0.5 → ^3.0.8
query-string ^7.1.1 → ^7.1.3
semantic-release ^19.0.2 → ^19.0.5
styled-components ^5.3.6 → ^5.3.11
tailwindcss ^3.4.7 → ^3.4.19
@commercelayer/js-auth ^6.3.1 → ^6.7.2
@headlessui/react ^1.5.0 → ^1.7.19
@next/eslint-plugin-next ^13.1.6 → ^13.5.11
@types/lodash ^4.14.195 → ^4.17.25
@types/react ^18.0.28 → ^18.3.31
@types/react-dom ^18.0.11 → ^18.3.7
dotenv ^16.3.1 → ^16.6.1
eslint ^8.34.0 → ^8.57.1
eslint-config-next ^13.1.6 → ^13.5.11
eslint-config-prettier ^8.6.0 → ^8.10.2
globby ^13.1.3 → ^13.2.2
next ^13.1.6 → ^13.5.11
postcss ^8.4.24 → ^8.5.28
postcss-preset-env ^7.4.1 → ^7.8.3
prettier ^2.5.1 → ^2.8.8
react ^18.2.0 → ^18.3.1
react-dom ^18.2.0 → ^18.3.1
@tailwindcss/aspect-ratio ^0.4.0 → ^0.4.2
@tailwindcss/forms ^0.4.0 → ^0.4.1
@tailwindcss/typography ^0.5.2 → ^0.5.20
axios ^0.26.0 → ^0.26.1
sharp ^0.32.1 → ^0.32.6
solutions/commercelayer-slackbot/package.json
@commercelayer/js-auth ^4.1.1 → ^4.3.0
@commercelayer/sdk ^4.25.0 → ^4.57.0
@slack/bolt ^3.13.1 → ^3.22.0
@supabase/supabase-js ^2.26.0 → ^2.116.0
dotenv ^16.0.3 → ^16.6.1
supabase ^1.45.2 → ^1.226.4
tslib ^2.6.0 → ^2.8.1
solutions/giftcard-tutorial/package.json
@commercelayer/react-components ^4.25.1 → ^4.29.7
@commercelayer/sdk ^6.44.0 → ^6.58.0
react ^19.0.0 → ^19.2.8
react-dom ^19.0.0 → ^19.2.8
solutions/js-sdk-sandbox/package.json
parcel ^2.12.0 → ^2.16.4
solutions/pay-with-tweet/package.json
@types/express ^4.17.21 → ^4.17.25
nodemon ^3.1.4 → ^3.1.14
@types/node ^22.0.2 → ^22.20.1
dotenv ^16.4.5 → ^16.6.1
express ^4.19.2 → ^4.22.2
tsc-watch ^6.2.0 → ^6.3.1
webhooks/expressjs-signature-verification/package.json
express ^4.19.2 → ^4.22.2
webhooks/sendgrid-templated-emails/package.json
@sendgrid/mail ^8.1.3 → ^8.1.6
dotenv ^16.4.5 → ^16.6.1
express ^4.19.2 → ^4.22.2
webhooks/twilio-sms-notification/package.json
dotenv ^16.4.5 → ^16.6.1
express ^4.19.2 → ^4.22.2
twilio ^5.2.2 → ^5.13.1
solutions/external-payment-gateway/packages/app/package.json
@types/react ^19.2.15 → ^19.2.18
@types/react-dom ^19.2.3 → ^19.2.7
react ^19.2.6 → ^19.2.8
react-dom ^19.2.6 → ^19.2.8
@commercelayer/sdk ^7.11.0 → ^7.12.1
@vitejs/plugin-react ^6.0.2 → ^6.1.1
react-router-dom ^7.15.1 → ^7.18.3
vite ^8.0.14 → ^8.2.2
solutions/external-payment-gateway/packages/mollie-gateway/package.json
@types/node ^25.9.1 → ^25.9.5
@commercelayer/sdk ^7.11.0 → ^7.12.1
@hono/node-server ^2.0.4 → ^2.1.1
@mollie/api-client ^4.5.0 → ^4.6.0
hono ^4.12.22 → ^4.13.7
tsx ^4.15.6 → ^4.23.13
Audit log
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ critical │ Next.js: Unauthenticated Remote Code Execution on │
│ │ windows-hosted servers │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.0 <15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-p293-qw3h-jr36 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ critical │ Next.js: Unauthenticated Remote Code Execution in │
│ │ Image Optimization API when AVIF files are used │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-2xp9-vwfh-vxw4 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js Server-Side Request Forgery in Server Actions │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.0 <14.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-fr5h-rqp8-mj6g │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Server-Side Request Forgery in axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.3.2 <=1.7.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.7.4 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-8hc4-vh64-cxmj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js authorization bypass vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.5.5 <14.2.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.2.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7gfc-8cq8-jh5f │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ axios Requests Vulnerable To Possible SSRF and │
│ │ Credential Leakage via Absolute URL │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <0.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-jr5f-v2jv-69x6 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ axios Requests Vulnerable To Possible SSRF and │
│ │ Credential Leakage via Absolute URL │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.8.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.8.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-jr5f-v2jv-69x6 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next Vulnerable to Denial of Service with Server │
│ │ Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.3.0 <14.2.34 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.2.34 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-mwv6-3258-q52c │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next has a Denial of Service with Server Components - │
│ │ Incomplete Fix Follow-Up │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.3.1-canary.0 <14.2.35 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.2.35 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-5j59-xgg2-r9c4 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios is vulnerable to DoS attack through lack of data │
│ │ size check │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.12.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.12.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4hjh-wcwx-xvwj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js HTTP request deserialization can lead to DoS │
│ │ when using insecure React Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.0.8 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.0.8 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-h25m-26qc-wcjf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has a ReDoS via repeated wildcards with │
│ │ non-matching literal in pattern │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.6 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=9.0.6 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>eslint-config-next>@typescript-eslint/ │
│ │ parser>@typescript-eslint/typescript-estree>minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-3ppc-4f35-3m26 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has ReDoS: matchOne() combinatorial │
│ │ backtracking via multiple non-adjacent GLOBSTAR │
│ │ segments │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>eslint-config-next>@typescript-eslint/ │
│ │ parser>@typescript-eslint/typescript-estree>minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7r86-cg39-jmmj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch ReDoS: nested *() extglobs generate │
│ │ catastrophically backtracking regular expressions │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>eslint-config-next>@typescript-eslint/ │
│ │ parser>@typescript-eslint/typescript-estree>minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-23c5-xmqv-rm74 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js has a Denial of Service with Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.5.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-q4gf-8mx6-v5v3 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY │
│ │ Protection Bypassed via RFC 1122 Loopback Subnet │
│ │ (127.0.0.0/8) in Axios 1.15.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.31.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pmwg-cvhr-8vh7 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY │
│ │ Protection Bypassed via RFC 1122 Loopback Subnet │
│ │ (127.0.0.0/8) in Axios 1.15.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pmwg-cvhr-8vh7 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Prototype Pollution Gadgets - Response │
│ │ Tampering, Data Exfiltration, and Request Hijacking │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.31.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pf86-5x62-jrwf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Prototype Pollution Gadgets - Response │
│ │ Tampering, Data Exfiltration, and Request Hijacking │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pf86-5x62-jrwf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Header Injection via Prototype Pollution │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.31.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-6chq-wfr3-2hj9 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Header Injection via Prototype Pollution │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-6chq-wfr3-2hj9 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios is Vulnerable to Denial of Service via __proto__ │
│ │ Key in mergeConfig │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.30.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.30.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-43fc-jf86-j433 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios is Vulnerable to Denial of Service via __proto__ │
│ │ Key in mergeConfig │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <=1.13.4 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.13.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-43fc-jf86-j433 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js Vulnerable to Denial of Service with Server │
│ │ Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-8h8q-6873-q5fj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios has prototype pollution read-side gadgets in │
│ │ HTTP adapter that allow credential injection and │
│ │ request hijacking │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.2 │
├─────────────────────┼──────────────────────────────────────────────────────��
...truncated...
Dependency update tracking
Date:
2026-09-09Branch:
chore/deps-update-202609091005Prerelease tag:
skippedNode.js:
24.xpnpm:
10.xThis issue tracks the automated dependency update. It will be closed automatically when the linked PR is merged.
Dependency update results
Semver bump log
Audit log