Skip to content

Bump next 16.3.6 (security) and lucide-react 1.47.0 - #71

Merged
AdamEXu merged 1 commit into
mainfrom
cursor/bump-next-security-lucide-cb4c
Sep 24, 2026
Merged

AdamEXu merged 1 commit into
mainfrom
cursor/bump-next-security-lucide-cb4c

Conversation

@AdamEXu

@AdamEXu AdamEXu commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

What & why

Frontend security/dependency bump. Next.js 16.3.6 is the official Sep 22 2026 security release for CVE-2026-94545 (ImageResponse RCE). Freshness hold overridden for this critical patch. eslint-config-next is matched to Next. lucide-react is bumped to 1.47.0 (not 1.48.0), including the pnpm.overrides pin.

Versions were already supply-chain checked — no other packages were changed.

Package From To
next 16.3.5 16.3.6 (CVE-2026-94545)
eslint-config-next 16.3.5 16.3.6
lucide-react ^1.46.0 (override 1.46.0) ^1.47.0 (override 1.47.0)

Held (intentional)

  • fumadocs-* (including fumadocs-mdx 14; fumadocs-mdx 15 is held)
  • posthog-js >=1.422.1 <1.425.0
  • TypeScript majors, ESLint 10, and other deps
  • lucide-react 1.48.0

Area

  • Frontend
  • Backend
  • Scraper
  • Convex
  • Infra / tooling

How tested

  • cd frontend && pnpm install with pnpm@10.30.3
  • pnpm typecheck (tsc --noEmit) passed
  • pnpm build (next build --turbopack) passed on Next.js 16.3.6 — compiled, TypeScript, and static generation all succeeded
  • pnpm lint still fails with pre-existing issues (chat hooks, generated .source, etc.) — no next/lucide breakage found

Security checklist

  • Endpoints returning user data enforce ownership / authorization (no IDOR — a user cannot read another user's data). — N/A (dependency bump only)
  • @auth_required is applied to routes that need authentication. — N/A
  • No SSRF: any outbound/scraped URL is validated (scheme + host) before it is fetched. — N/A
  • No secrets committed — no .env, *.db, keys, or credentials in the diff.
  • Flask debug mode is not forced on in a production code path. — N/A
  • OAuth tokens stay encrypted at rest and are never logged or returned in responses. — N/A

Checks

  • cd frontend && pnpm typecheck passes.
  • cd frontend && pnpm build passes (Next.js 16.3.6).
  • cd frontend && pnpm lint passes. (pre-existing failures; unchanged by this bump)
  • Backend still starts and affected endpoints work (make dev-backend). — N/A (frontend deps only)
Open in Web Open in Cursor 

Patch Next.js to 16.3.6 for CVE-2026-94545 (ImageResponse RCE), match
eslint-config-next, and bump lucide-react to 1.47.0 including the pnpm override.

Co-authored-by: Adam Xu <AdamEXu@users.noreply.github.com>
@greptile-apps

greptile-apps Bot commented Sep 24, 2026

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no actionable issue was identified.

Summary

The PR updates the frontend dependency manifest and lockfile.

  • Bumps Next.js and eslint-config-next from 16.3.5 to 16.3.6.
  • Bumps lucide-react from 1.46.0 to 1.47.0, including its exact pnpm override.

Reviews (1) · Last reviewed commit: "chore(deps): bump next 16.3.6 (security)..."

@AdamEXu
AdamEXu merged commit f2e922e into main Sep 24, 2026
7 checks passed
@AdamEXu
AdamEXu deleted the cursor/bump-next-security-lucide-cb4c branch September 24, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants