Skip to content

[Snyk] Upgrade react-dom from 19.0.0 to 19.2.3 - #72

Open
RohitKini wants to merge 1 commit into
mainfrom
snyk-upgrade-2d7196d0f8abff0a2203c5cc49b3ddab
Open

[Snyk] Upgrade react-dom from 19.0.0 to 19.2.3#72
RohitKini wants to merge 1 commit into
mainfrom
snyk-upgrade-2d7196d0f8abff0a2203c5cc49b3ddab

Conversation

@RohitKini

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to upgrade react-dom from 19.0.0 to 19.2.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 230 versions ahead of your current version.

  • The recommended version was released 2 months ago.

Release notes
Package name: react-dom
  • 19.2.3 - 2025-12-11

    React Server Components

  • 19.2.2 - 2025-12-11

    React Server Components

  • 19.2.1 - 2025-12-03

    React Server Components

  • 19.2.0 - 2025-10-01

    Below is a list of all new features, APIs, and bug fixes.

    Read the React 19.2 release post for more information.

    New React Features

    • <Activity>: A new API to hide and restore the UI and internal state of its children.
    • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
    • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
    • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

    New React DOM Features

    • Added resume APIs for partial pre-rendering with Web Streams:
    • Added resume APIs for partial pre-rendering with Node Streams:
    • Updated prerender APIs to return a postponed state that can be passed to the resume APIs.

    Notable changes

    • React DOM now batches suspense boundary reveals, matching the behavior of client side rendering. This change is especially noticeable when animating the reveal of Suspense boundaries e.g. with the upcoming <ViewTransition> Component. React will batch as much reveals as possible before the first paint while trying to hit popular first-contentful paint metrics.
    • Add Node Web Streams (prerender, renderToReadableStream) to server-side-rendering APIs for Node.js
    • Use underscore instead of : IDs generated by useId

    All Changes

    React

    React DOM

    React Server Components

    React Reconciler

    eslint-plugin-react-hooks@6.1.0

    Note: Version 6.0.0 was mistakenly released and immediately deprecated and untagged on npm. This is the first official 6.x major release and includes breaking changes.

    • Breaking: Require Node.js 18 or newer. (@ michaelfaith in #32458)
    • Breaking: Flat config is now the default recommended preset. Legacy config moved to recommended-legacy. (@ michaelfaith in #32457)
    • New Violations: Disallow calling use within try/catch blocks. (@ poteto in #34040)
    • New Violations: Disallow calling useEffectEvent functions in arbitrary closures. (@ jbrown215 in #33544)
    • Handle React.useEffect in addition to useEffect in rules-of-hooks. (@ Ayc0 in #34076)
    • Added react-hooks settings config option that to accept additionalEffectHooks that are used across exhaustive-deps and rules-of-hooks rules. (@ jbrown215) in #34497
  • 19.2.0-canary-fa3feba6-20250623 - 2025-06-23
  • 19.2.0-canary-f9ae0a4c-20250527 - 2025-05-27
  • 19.2.0-canary-f7396427-20250501 - 2025-05-02
  • 19.2.0-canary-f508edc8-20250818 - 2025-08-18
  • 19.2.0-canary-f3a80361-20250911 - 2025-09-11
  • 19.2.0-canary-f1e70b5e-20250811 - 2025-08-11
  • 19.2.0-canary-f1222f76-20250812 - 2025-08-13
  • 19.2.0-canary-ef8b6fa2-20250702 - 2025-07-03
  • 19.2.0-canary-ef889445-20250930 - 2025-09-30
  • 19.2.0-canary-edac0dde-20250723 - 2025-07-23
  • 19.2.0-canary-eaee5308-20250728 - 2025-07-28
  • 19.2.0-canary-ea05b750-20250408 - 2025-04-09
  • 19.2.0-canary-e9db3cc2-20250501 - 2025-05-01
  • 19.2.0-canary-e9638c33-20250721 - 2025-07-21
  • 19.2.0-canary-e6dc25da-20250709 - 2025-07-09
  • 19.2.0-canary-e5dd82a7-20250401 - 2025-04-01
  • 19.2.0-canary-e2332183-20250924 - 2025-09-24
  • 19.2.0-canary-dffacc7b-20250717 - 2025-07-17
  • 19.2.0-canary-df38ac9a-20250926 - 2025-09-26
  • 19.2.0-canary-de5a1b20-20250905 - 2025-09-05
  • 19.2.0-canary-d92056ef-20250627 - 2025-06-27
  • 19.2.0-canary-d85f86cf-20250514 - 2025-05-14
  • 19.2.0-canary-d85ec5f5-20250716 - 2025-07-16
  • 19.2.0-canary-d415fd3e-20250919 - 2025-09-19
  • 19.2.0-canary-d15d7fd7-20250929 - 2025-09-29
  • 19.2.0-canary-cee7939b-20250625 - 2025-06-25
  • 19.2.0-canary-c498bfce-20250426 - 2025-04-28
  • 19.2.0-canary-c4676e72-20250520 - 2025-05-20
  • 19.2.0-canary-c44e4a25-20250409 - 2025-04-10
  • 19.2.0-canary-c260b38d-20250731 - 2025-07-31
  • 19.2.0-canary-c129c242-20250505 - 2025-05-05
  • 19.2.0-canary-c0464aed-20250523 - 2025-05-26
  • 19.2.0-canary-befc1246-20250708 - 2025-07-08
  • 19.2.0-canary-be11cb5c-20250804 - 2025-08-04
  • 19.2.0-canary-bdb4a96f-20250801 - 2025-08-01
  • 19.2.0-canary-bc6184dd-20250417 - 2025-04-18
  • 19.2.0-canary-bbc13fa1-20250624 - 2025-06-24
  • 19.2.0-canary-bb6f0c8d-20250901 - 2025-09-01
  • 19.2.0-canary-b9cfa0d3-20250505 - 2025-05-05
  • 19.2.0-canary-b9a04536-20250904 - 2025-09-04
  • 19.2.0-canary-b94603b9-20250513 - 2025-05-13
  • 19.2.0-canary-b7e2de63-20250611 - 2025-06-11
  • 19.2.0-canary-b6c0aa88-20250609 - 2025-06-09
  • 19.2.0-canary-b4477d38-20250605 - 2025-06-05
  • 19.2.0-canary-b1b0955f-20250901 - 2025-09-01
  • 19.2.0-canary-b10cb4c0-20250403 - 2025-04-03
  • 19.2.0-canary-b0c1dc01-20250925 - 2025-09-25
  • 19.2.0-canary-b07717d8-20250528 - 2025-05-28
  • 19.2.0-canary-b04254fd-20250415 - 2025-04-16
  • 19.2.0-canary-ac7820a9-20250811 - 2025-08-11
  • 19.2.0-canary-ab859e31-20250606 - 2025-06-06
  • 19.2.0-canary-aad7c664-20250829 - 2025-08-29
  • 19.2.0-canary-a96a0f39-20250815 - 2025-08-15
  • 19.2.0-canary-a7a11657-20250708 - 2025-07-08
  • 19.2.0-canary-a00ca6f6-20250611 - 2025-06-11
  • 19.2.0-canary-9be531cd-20250729 - 2025-07-29
  • 19.2.0-canary-99efc627-20250523 - 2025-05-23
  • 19.2.0-canary-97cdd5d3-20250710 - 2025-07-11
  • 19.2.0-canary-9784cb37-20250730 - 2025-07-30
  • 19.2.0-canary-96c61b7f-20250709 - 2025-07-10
  • 19.2.0-canary-93d7aa69-20250912 - 2025-09-12
  • 19.2.0-canary-914319ae-20250423 - 2025-04-23
  • 19.2.0-canary-8e60cb7e-20250902 - 2025-09-02
  • 19.2.0-canary-8d7b5e49-20250827 - 2025-08-28
  • 19.2.0-canary-8ce15b0f-20250522 - 2025-05-22
  • 19.2.0-canary-8bb7241f-20250926 - 2025-09-26
  • 19.2.0-canary-8a8e9a7e-20250912 - 2025-09-12
  • 19.2.0-canary-89a803fc-20250828 - 2025-08-28
  • 19.2.0-canary-886b3d36-20250910 - 2025-09-10
  • 19.2.0-canary-873f7112-20250821 - 2025-08-21
  • 19.2.0-canary-86181134-20251001 - 2025-10-01
  • 19.2.0-canary-84af9085-20250917 - 2025-09-18
  • 19.2.0-canary-83c88ad4-20250923 - 2025-09-23
  • 19.2.0-canary-7deda941-20250804 - 2025-08-05
  • 19.2.0-canary-7a2c7045-20250506 - 2025-05-06
  • 19.2.0-canary-79d9aed7-20250620 - 2025-06-20
  • 19.2.0-canary-7513996f-20250722 - 2025-07-22
  • 19.2.0-canary-73aa744b-20250702 - 2025-07-02
  • 19.2.0-canary-7216c0f0-20250630 - 2025-07-01
  • 19.2.0-canary-72135096-20250421 - 2025-04-22
  • 19.2.0-canary-6eda5347-20250918 - 2025-09-19
  • 19.2.0-canary-6de32a5a-20250822 - 2025-08-22
  • 19.2.0-canary-6b70072c-20250909 - 2025-09-09
  • 19.2.0-canary-6a7650c7-20250405 - 2025-04-05
  • 19.2.0-canary-67a44bcd-20250915 - 2025-09-15
  • 19.2.0-canary-66f09bd0-20250806 - 2025-08-06
  • 19.2.0-canary-65c4decb-20250630 - 2025-06-30
  • 19.2.0-canary-63779030-20250328 - 2025-03-31
  • 19.2.0-canary-60b5271a-20250709 - 2025-07-09
  • 19.2.0-canary-5e0c951b-20250916 - 2025-09-16
  • 19.2.0-canary-5dc00d6b-20250428 - 2025-04-28
  • 19.2.0-canary-5d87cd22-20250704 - 2025-07-04
  • 19.2.0-canary-56408a5b-20250610 - 2025-06-10
  • 19.2.0-canary-548235db-20251001 - 2025-10-01
  • 19.2.0-canary-540cd652-20250403 - 2025-04-04
  • 19.2.0-canary-534bed5f-20250813 - 2025-08-13
  • 19.2.0-canary-526dd340-20250602 - 2025-06-02
  • 19.2.0-canary-4db4b21c-20250626 - 2025-06-26
  • 19.2.0-canary-4a45ba92-20250515 - 2025-05-15
  • 19.2.0-canary-4a36d3ea-20250416 - 2025-04-17
  • 19.2.0-canary-462d08f9-20250517 - 2025-05-19
  • 19.2.0-canary-4448b187-20250515 - 2025-05-16
  • 19.2.0-canary-4123f6b7-20250826 - 2025-08-26
  • 19.2.0-canary-408d055a-20250430 - 2025-04-30
  • 19.2.0-canary-3fbfb9ba-20250409 - 2025-04-09
  • 19.2.0-canary-3fb190f7-20250908 - 2025-09-08
  • 19.2.0-canary-3d14fcf0-20250724 - 2025-07-24
  • 19.2.0-canary-39cad7af-20250411 - 2025-04-14
  • 19.2.0-canary-3958d5d8-20250807 - 2025-08-07
  • 19.2.0-canary-38ef6550-20250508 - 2025-05-08
  • 19.2.0-canary-3820740a-20250509 - 2025-05-12
  • 19.2.0-canary-379a083b-20250813 - 2025-08-14
  • 19.2.0-canary-37054867-20250604 - 2025-06-04
  • 19.2.0-canary-33a1095d-20250827 - 2025-08-27
  • 19.2.0-canary-33661467-20250407 - 2025-04-07
  • 19.2.0-canary-3302d1f7-20250903 - 2025-09-03
  • 19.2.0-canary-2f0e7e57-20250715 - 2025-07-15
  • 19.2.0-canary-280ff6fe-20250606 - 2025-06-06
  • 19.2.0-canary-2805f0ed-20250903 - 2025-09-03
  • 19.2.0-canary-23884812-20250520 - 2025-05-21
  • 19.2.0-canary-223f81d8-20250707 - 2025-07-07
  • 19.2.0-canary-21fdf308-20250508 - 2025-05-09
  • 19.2.0-canary-1eca9a27-20250922 - 2025-09-22
  • 19.2.0-canary-1dc3bdea-20250812 - 2025-08-12
  • 19.2.0-canary-1d6c8168-20250411 - 2025-04-11
  • 19.2.0-canary-1bd1f01f-20251001 - 2025-10-01
  • 19.2.0-canary-1ae0a845-20250603 - 2025-06-03
  • 19.2.0-canary-19baee81-20250725 - 2025-07-25
  • 19.2.0-canary-197d6a04-20250424 - 2025-04-24
  • 19.2.0-canary-143d3e1b-20250425 - 2025-04-25
  • 19.2.0-canary-14094f80-20250529 - 2025-05-29
  • 19.2.0-canary-12bc60f5-20250613 - 2025-06-13
  • 19.2.0-canary-128abcfa-20250917 - 2025-09-17
  • 19.2.0-canary-0ff1d13b-20250507 - 2025-05-07
  • 19.2.0-canary-0bdb9206-20250818 - 2025-08-19
  • 19.2.0-canary-06e89951-20250620 - 2025-06-20
  • 19.2.0-canary-040f8286-20250402 - 2025-04-02
  • 19.2.0-canary-03fda05d-20250820 - 2025-08-20
  • 19.2.0-canary-0038c501-20250429 - 2025-04-29
  • 19.1.5 - 2026-01-26
  • 19.1.4 - 2025-12-11
  • 19.1.3 - 2025-12-11

    React Server Components

  • 19.1.2 - 2025-12-03

    React Server Components

  • 19.1.1 - 2025-07-28

    React

    • Fixed Owner Stacks to work with ES2015 function.name semantics (#33680 by @ hoxyq)
  • 19.1.0 - 2025-03-28
  • 19.1.0-canary-ff628334-20250205 - 2025-02-06
  • 19.1.0-canary-fcb4e0f1-20250219 - 2025-02-20
  • 19.1.0-canary-fc8a898d-20241226 - 2024-12-27
  • 19.1.0-canary-fbcda19a-20250317 - 2025-03-17
  • 19.1.0-canary-f9d78089-20250306 - 2025-03-07
  • 19.1.0-canary-f83903bf-20250212 - 2025-02-12
  • 19.1.0-canary-f457d0b4-20250313 - 2025-03-13
  • 19.1.0-canary-f0edf41e-20250115 - 2025-01-14
  • 19.1.0-canary-ef979d47-20241218 - 2024-12-18
  • 19.1.0-canary-ef4bc8b4-20250328 - 2025-03-28
  • 19.1.0-canary-ebc22ef7-20250225 - 2025-02-26
  • 19.1.0-canary-e670e72f-20250214 - 2025-02-14
  • 19.1.0-canary-e1e74071-20250321 - 2025-03-21
  • 19.1.0-canary-e06c72fc-20241215 - 2024-12-16
  • 19.1.0-canary-e03ac20f-20250305 - 2025-03-05
  • 19.1.0-canary-de82912e-20241220 - 2024-12-20
  • 19.1.0-canary-de1eaa26-20250124 - 2025-01-24
  • 19.1.0-canary-db7dfe05-20250319 - 2025-03-19
  • 19.1.0-canary-d85cf3e5-20250205 - 2025-02-05
  • 19.1.0-canary-d55cc79b-20250228 - 2025-02-28
  • 19.1.0-canary-d46b04a2-20250117 - 2025-01-17
  • 19.1.0-canary-d4287258-20241217 - 2024-12-17
  • 19.1.0-canary-d331ba04-20250307 - 2025-03-10
  • 19.1.0-canary-cd90a4d8-20250210 - 2025-02-11
  • 19.1.0-canary-cbbe8666-20250213 - 2025-02-13
  • 19.1.0-canary-cabd8a0e-20250113 - 2025-01-13
  • 19.1.0-canary-c69a5fc5-20250318 - 2025-03-18
  • 19.1.0-canary-c492f975-20250128 - 2025-01-29
  • 19.1.0-canary-c01b8058-20241229 - 2024-12-30
  • 19.1.0-canary-bb9a24d9-20250130 - 2025-01-30
  • 19.1.0-canary-b3a95caf-20250113 - 2025-01-14
  • 19.1.0-canary-b158439a-20250115 - 2025-01-15
  • 19.1.0-canary-ae9017ce-20250122 - 2025-01-23
  • 19.1.0-canary-a84862db-20250218 - 2025-02-19
  • 19.1.0-canary-a4f9bd58-20250319 - 2025-03-20
  • 19.1.0-canary-a4b2d0d5-20250203 - 2025-02-03
  • 19.1.0-canary-9ff42a87-20250130 - 2025-01-31
  • 19.1.0-canary-9eabb373-20250124 - 2025-01-27
  • 19.1.0-canary-9b62ee71-20250122 - 2025-01-22
  • 19.1.0-canary-97d79495-20241223 - 2024-12-24
  • 19.1.0-canary-9463d51e-20241219 - 2024-12-19
  • 19.1.0-canary-93b58361-20250209 - 2025-02-10
  • 19.1.0-canary-8a7b487e-20250218 - 2025-02-18
  • 19.1.0-canary-8759c5c8-20250207 - 2025-02-07
  • 19.1.0-canary-7eb8234f-20241218 - 2024-12-18
  • 19.1.0-canary-7b402084-20250107 - 2025-01-07
  • 19.1.0-canary-74ea0c73-20250109 - 2025-01-09
  • 19.1.0-canary-740a4f7a-20250325 - 2025-03-25
  • 19.1.0-canary-7130d0c6-20241212 - 2024-12-12
  • 19.1.0-canary-6aa8254b-20250312 - 2025-03-12
  • 19.1.0-canary-694d3e1a-20241231 - 2025-01-01
  • 19.1.0-canary-6907aa2a-20241220 - 2024-12-23
  • 19.1.0-canary-662957cc-20250221 - 2025-02-21
  • 19.1.0-canary-62208bee-20250102 - 2025-01-02
  • 19.1.0-canary-5b51a2b9-20250116 - 2025-01-16
  • 19.1.0-canary-540efebc-20250112 - 2025-01-12
  • 19.1.0-canary-5398b711-20250314 - 2025-03-14
  • 19.1.0-canary-518d06d2-20241219 - 2024-12-19
  • 19.1.0-canary-4dff0e62-20241213 - 2024-12-13
  • 19.1.0-canary-4632e36a-20250216 - 2025-02-17
  • 19.1.0-canary-443b7ff2-20250303 - 2025-03-04
  • 19.1.0-canary-4280563b-20250326 - 2025-03-27
  • 19.1.0-canary-42687267-20250108 - 2025-01-08
  • 19.1.0-canary-3ce77d55-20250106 - 2025-01-06
  • 19.1.0-canary-3b009b4c-20250102 - 2025-01-03
  • 19.1.0-canary-37906d4d-20250127 - 2025-01-28
  • 19.1.0-canary-32b0cad8-20250213 - 2025-02-13
  • 19.1.0-canary-313332d1-20250326 - 2025-03-26
  • 19.1.0-canary-2980f277-20250301 - 2025-03-03
  • 19.1.0-canary-25677265-20250224 - 2025-02-24
  • 19.1.0-canary-22e39ea7-20250225 - 2025-02-25
  • 19.1.0-canary-18eaf51b-20250118 - 2025-01-20
  • 19.1.0-canary-130095f7-20241212 - 2024-12-12
  • 19.1.0-canary-0ca3deeb-20250311 - 2025-03-11
  • 19.1.0-canary-0a82580b-20250203 - 2025-02-04
  • 19.1.0-canary-056073de-20250109 - 2025-01-10
  • 19.1.0-canary-029e8bd6-20250306 - 2025-03-06
  • 19.0.4 - 2026-01-26
  • 19.0.3 - 2025-12-11

    React Server Components

  • 19.0.2 - 2025-12-11

    React Server Components

  • 19.0.1 - 2025-12-03

    React Server Components

  • 19.0.0 - 2024-12-05
from react-dom GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade react-dom from 19.0.0 to 19.2.3.

See this package in npm:
react-dom

See this project in Snyk:
https://app.snyk.io/org/rohitkini/project/***REDACTED***?utm_source=github&utm_medium=referral&page=upgrade-pr
@RohitKini
RohitKini requested a review from a team as a code owner February 6, 2026 08:52
@priyadarshan-khadtale-cstk
priyadarshan-khadtale-cstk force-pushed the snyk-upgrade-2d7196d0f8abff0a2203c5cc49b3ddab branch from 20be4a9 to 08dc4fa Compare August 13, 2026 09:55
@snyk-io

snyk-io Bot commented Aug 13, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 1 0 10 ✅ Passed
🟠 High Severity 30 0 25 ❌ Failed
🟡 Medium Severity 39 0 500 ✅ Passed
🔵 Low Severity 7 0 1000 ✅ Passed

⏱️ SLA Breach Summary

⚠️ Warning: The following vulnerabilities have exceeded their SLA thresholds (days since publication).

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 1 0 15 / 30 days ❌ Failed
🟠 High 20 0 30 / 120 days ❌ Failed
🟡 Medium 20 0 90 / 365 days ❌ Failed
🔵 Low 0 0 180 / 365 days ✅ Passed

🔴 Critical Severity - SLA Breached Issues (with fixes)

Showing 1 issue(s) that have exceeded the 15-day SLA threshold:

  1. CRLF Injection
    • ID: SNYK-JS-UNDICI-17372658
    • Package: undici@7.16.0
    • Published: 55 days ago (SLA: 15 days)
    • CVSS Score: 9.2
    • CVE: CVE-2026-9679

🟠 High Severity - SLA Breached Issues (with fixes)

Showing 20 issue(s) that have exceeded the 30-day SLA threshold:

  1. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15104645
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59471
  2. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15105315
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59472
  3. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-QS-15268416
    • Package: qs@6.14.1
    • Published: 182 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2026-2391
  4. Uncaught Exception

    • ID: SNYK-JS-UNDICI-15518064
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-1528
  5. Improper Handling of Highly Compressed Data (Data Amplification)

    • ID: SNYK-JS-UNDICI-15518068
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-1526
  6. Uncaught Exception

    • ID: SNYK-JS-UNDICI-15518070
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-2229
  7. Arbitrary Code Injection

    • ID: SNYK-JS-LODASHES-15869627
    • Package: lodash-es@4.17.21
    • Published: 133 days ago (SLA: 30 days)
    • CVSS Score: 8.6
    • CVE: CVE-2026-4800
  8. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15921797
    • Package: next@16.0.10
    • Published: 128 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23864
  9. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15954202
    • Package: next@16.0.10
    • Published: 125 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23869
  10. Allocation of Resources Without Limits or Throttling

  • ID: SNYK-JS-NEXT-16638674
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-23870
  1. Allocation of Resources Without Limits or Throttling
  • ID: SNYK-JS-NEXT-16638678
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-44579
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638679
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.6
  • CVE: CVE-2026-44574
  1. Allocation of Resources Without Limits or Throttling
  • ID: SNYK-JS-NEXT-16638680
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.2
  • CVE: CVE-2026-44577
  1. Server-side Request Forgery (SSRF)
  • ID: SNYK-JS-NEXT-16638682
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 7.7
  • CVE: CVE-2026-44578
  1. Incorrect Authorization
  • ID: SNYK-JS-NEXT-16638683
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.2
  • CVE: CVE-2026-44573
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638685
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-44575
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638686
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-45109
  1. Use of Cache Containing Sensitive Information
  • ID: SNYK-JS-UNDICI-17372697
  • Package: undici@7.16.0
  • Published: 55 days ago (SLA: 30 days)
  • CVSS Score: 8.9
  • CVE: CVE-2026-9678
  1. Allocation of Resources Without Limits or Throttling
  • ID: SNYK-JS-UNDICI-17372754
  • Package: undici@7.16.0
  • Published: 55 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-12151
  1. Permissive List of Allowed Inputs
  • ID: SNYK-JS-UNDICI-17372758
  • Package: undici@7.16.0
  • Published: 55 days ago (SLA: 30 days)
  • CVSS Score: 8.3
  • CVE: CVE-2026-11525

🟡 Medium Severity - SLA Breached Issues (with fixes)

Showing 20 issue(s) that have exceeded the 90-day SLA threshold:

  1. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-UNDICI-14943963
    • Package: undici@7.16.0
    • Published: 209 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-22036
  2. Prototype Pollution

    • ID: SNYK-JS-LODASHES-15053836
    • Package: lodash-es@4.17.21
    • Published: 203 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2025-13465
  3. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15371376
    • Package: dompurify@3.3.0
    • Published: 161 days ago (SLA: 90 days)
    • CVSS Score: 5.1
    • CVE: CVE-2026-0540
  4. HTTP Request Smuggling

    • ID: SNYK-JS-UNDICI-15518061
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-1525
  5. CRLF Injection

    • ID: SNYK-JS-UNDICI-15518072
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 90 days)
    • CVSS Score: 5.1
    • CVE: CVE-2026-1527
  6. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15674556
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-27980
  7. Cross-site Request Forgery (CSRF)

    • ID: SNYK-JS-NEXT-15674557
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-27978
  8. HTTP Request Smuggling

    • ID: SNYK-JS-NEXT-15674558
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.3
    • CVE: CVE-2026-29057
  9. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15810938
    • Package: dompurify@3.3.0
    • Published: 136 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65914
  10. Prototype Pollution

  • ID: SNYK-JS-LODASHES-15869621
  • Package: lodash-es@4.17.21
  • Published: 133 days ago (SLA: 90 days)
  • CVSS Score: 6.9
  • CVE: CVE-2026-2950
  1. Prototype Pollution
  • ID: SNYK-JS-DOMPURIFY-15874903
  • Package: dompurify@3.3.0
  • Published: 132 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-65913
  1. Permissive List of Allowed Inputs
  • ID: SNYK-JS-DOMPURIFY-15874905
  • Package: dompurify@3.3.0
  • Published: 132 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-65912
  1. Operator Precedence Logic Error
  • ID: SNYK-JS-DOMPURIFY-16078387
  • Package: dompurify@3.3.0
  • Published: 119 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41240
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-DOMPURIFY-16132234
  • Package: dompurify@3.3.0
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-41238
  1. Improper Validation of Specified Index, Position, or Offset in Input
  • ID: SNYK-JS-UUID-16133035
  • Package: uuid@8.3.2
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41907
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-POSTCSS-16189065
  • Package: postcss@8.4.31
  • Published: 111 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-41305
  1. Acceptance of Extraneous Untrusted Data With Trusted Data
  • ID: SNYK-JS-NEXT-16638675
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44572
  1. Interpretation Conflict
  • ID: SNYK-JS-NEXT-16638676
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44576
  1. Use of Weak Hash
  • ID: SNYK-JS-NEXT-16638677
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44582
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-NEXT-16638681
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-44580

❌ BUILD FAILED - Security checks failed

Please review and fix the security vulnerabilities before merging.

1 similar comment
@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 1 0 10 ✅ Passed
🟠 High Severity 30 0 25 ❌ Failed
🟡 Medium Severity 39 0 500 ✅ Passed
🔵 Low Severity 7 0 1000 ✅ Passed

⏱️ SLA Breach Summary

⚠️ Warning: The following vulnerabilities have exceeded their SLA thresholds (days since publication).

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 1 0 15 / 30 days ❌ Failed
🟠 High 20 0 30 / 120 days ❌ Failed
🟡 Medium 20 0 90 / 365 days ❌ Failed
🔵 Low 0 0 180 / 365 days ✅ Passed

🔴 Critical Severity - SLA Breached Issues (with fixes)

Showing 1 issue(s) that have exceeded the 15-day SLA threshold:

  1. CRLF Injection
    • ID: SNYK-JS-UNDICI-17372658
    • Package: undici@7.16.0
    • Published: 55 days ago (SLA: 15 days)
    • CVSS Score: 9.2
    • CVE: CVE-2026-9679

🟠 High Severity - SLA Breached Issues (with fixes)

Showing 20 issue(s) that have exceeded the 30-day SLA threshold:

  1. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15104645
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59471
  2. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15105315
    • Package: next@16.0.10
    • Published: 197 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2025-59472
  3. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-QS-15268416
    • Package: qs@6.14.1
    • Published: 182 days ago (SLA: 30 days)
    • CVSS Score: 8.2
    • CVE: CVE-2026-2391
  4. Uncaught Exception

    • ID: SNYK-JS-UNDICI-15518064
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-1528
  5. Improper Handling of Highly Compressed Data (Data Amplification)

    • ID: SNYK-JS-UNDICI-15518068
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-1526
  6. Uncaught Exception

    • ID: SNYK-JS-UNDICI-15518070
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-2229
  7. Arbitrary Code Injection

    • ID: SNYK-JS-LODASHES-15869627
    • Package: lodash-es@4.17.21
    • Published: 133 days ago (SLA: 30 days)
    • CVSS Score: 8.6
    • CVE: CVE-2026-4800
  8. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15921797
    • Package: next@16.0.10
    • Published: 128 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23864
  9. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15954202
    • Package: next@16.0.10
    • Published: 125 days ago (SLA: 30 days)
    • CVSS Score: 8.7
    • CVE: CVE-2026-23869
  10. Allocation of Resources Without Limits or Throttling

  • ID: SNYK-JS-NEXT-16638674
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-23870
  1. Allocation of Resources Without Limits or Throttling
  • ID: SNYK-JS-NEXT-16638678
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-44579
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638679
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.6
  • CVE: CVE-2026-44574
  1. Allocation of Resources Without Limits or Throttling
  • ID: SNYK-JS-NEXT-16638680
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.2
  • CVE: CVE-2026-44577
  1. Server-side Request Forgery (SSRF)
  • ID: SNYK-JS-NEXT-16638682
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 7.7
  • CVE: CVE-2026-44578
  1. Incorrect Authorization
  • ID: SNYK-JS-NEXT-16638683
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.2
  • CVE: CVE-2026-44573
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638685
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-44575
  1. Authentication Bypass Using an Alternate Path or Channel
  • ID: SNYK-JS-NEXT-16638686
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-45109
  1. Use of Cache Containing Sensitive Information
  • ID: SNYK-JS-UNDICI-17372697
  • Package: undici@7.16.0
  • Published: 55 days ago (SLA: 30 days)
  • CVSS Score: 8.9
  • CVE: CVE-2026-9678
  1. Allocation of Resources Without Limits or Throttling
  • ID: SNYK-JS-UNDICI-17372754
  • Package: undici@7.16.0
  • Published: 55 days ago (SLA: 30 days)
  • CVSS Score: 8.7
  • CVE: CVE-2026-12151
  1. Permissive List of Allowed Inputs
  • ID: SNYK-JS-UNDICI-17372758
  • Package: undici@7.16.0
  • Published: 55 days ago (SLA: 30 days)
  • CVSS Score: 8.3
  • CVE: CVE-2026-11525

🟡 Medium Severity - SLA Breached Issues (with fixes)

Showing 20 issue(s) that have exceeded the 90-day SLA threshold:

  1. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-UNDICI-14943963
    • Package: undici@7.16.0
    • Published: 209 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-22036
  2. Prototype Pollution

    • ID: SNYK-JS-LODASHES-15053836
    • Package: lodash-es@4.17.21
    • Published: 203 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2025-13465
  3. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15371376
    • Package: dompurify@3.3.0
    • Published: 161 days ago (SLA: 90 days)
    • CVSS Score: 5.1
    • CVE: CVE-2026-0540
  4. HTTP Request Smuggling

    • ID: SNYK-JS-UNDICI-15518061
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-1525
  5. CRLF Injection

    • ID: SNYK-JS-UNDICI-15518072
    • Package: undici@7.16.0
    • Published: 153 days ago (SLA: 90 days)
    • CVSS Score: 5.1
    • CVE: CVE-2026-1527
  6. Allocation of Resources Without Limits or Throttling

    • ID: SNYK-JS-NEXT-15674556
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.9
    • CVE: CVE-2026-27980
  7. Cross-site Request Forgery (CSRF)

    • ID: SNYK-JS-NEXT-15674557
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-27978
  8. HTTP Request Smuggling

    • ID: SNYK-JS-NEXT-15674558
    • Package: next@16.0.10
    • Published: 148 days ago (SLA: 90 days)
    • CVSS Score: 6.3
    • CVE: CVE-2026-29057
  9. Cross-site Scripting (XSS)

    • ID: SNYK-JS-DOMPURIFY-15810938
    • Package: dompurify@3.3.0
    • Published: 136 days ago (SLA: 90 days)
    • CVSS Score: 5.3
    • CVE: CVE-2026-65914
  10. Prototype Pollution

  • ID: SNYK-JS-LODASHES-15869621
  • Package: lodash-es@4.17.21
  • Published: 133 days ago (SLA: 90 days)
  • CVSS Score: 6.9
  • CVE: CVE-2026-2950
  1. Prototype Pollution
  • ID: SNYK-JS-DOMPURIFY-15874903
  • Package: dompurify@3.3.0
  • Published: 132 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-65913
  1. Permissive List of Allowed Inputs
  • ID: SNYK-JS-DOMPURIFY-15874905
  • Package: dompurify@3.3.0
  • Published: 132 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-65912
  1. Operator Precedence Logic Error
  • ID: SNYK-JS-DOMPURIFY-16078387
  • Package: dompurify@3.3.0
  • Published: 119 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41240
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-DOMPURIFY-16132234
  • Package: dompurify@3.3.0
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-41238
  1. Improper Validation of Specified Index, Position, or Offset in Input
  • ID: SNYK-JS-UUID-16133035
  • Package: uuid@8.3.2
  • Published: 112 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-41907
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-POSTCSS-16189065
  • Package: postcss@8.4.31
  • Published: 111 days ago (SLA: 90 days)
  • CVSS Score: 5.3
  • CVE: CVE-2026-41305
  1. Acceptance of Extraneous Untrusted Data With Trusted Data
  • ID: SNYK-JS-NEXT-16638675
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44572
  1. Interpretation Conflict
  • ID: SNYK-JS-NEXT-16638676
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44576
  1. Use of Weak Hash
  • ID: SNYK-JS-NEXT-16638677
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 6.3
  • CVE: CVE-2026-44582
  1. Cross-site Scripting (XSS)
  • ID: SNYK-JS-NEXT-16638681
  • Package: next@16.0.10
  • Published: 93 days ago (SLA: 90 days)
  • CVSS Score: 5.1
  • CVE: CVE-2026-44580

❌ BUILD FAILED - Security checks failed

Please review and fix the security vulnerabilities before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants