-
Notifications
You must be signed in to change notification settings - Fork 65
Upgrade React/NextJS version to fix CVE-2025-55182 #370
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
cc @Jitmisra, I cannot add you as a reviewer since you haven't joined the Apache group yet. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR upgrades React, Next.js, and related dependencies to address CVE-2025-55182, a critical RCE vulnerability in React Server Components. The upgrade includes moving from Next.js 15.5.4 to 16.0.7, React 19.2.0 to 19.2.1, and ESLint 8 to 9.39.1.
- Upgrades Next.js from 15.5.4 to ^16.0.7 and React from 19.2.0 to ^19.2.1
- Updates TypeScript configuration including JSX compiler option and dev types inclusion
- Upgrades ESLint from ^8 to ^9.39.1 and related type definitions
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| webui/package.json | Updates React, Next.js, ESLint, and type definition versions to address security vulnerability |
| webui/tsconfig.json | Modifies JSX compilation setting, adds dev types to includes, and reformats configuration file |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## unstable #370 +/- ##
============================================
+ Coverage 43.38% 49.14% +5.75%
============================================
Files 37 45 +8
Lines 2971 3783 +812
============================================
+ Hits 1289 1859 +570
- Misses 1544 1716 +172
- Partials 138 208 +70
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
BTW since this is a major version update of nextjs, have you tried to check if the webui works well after the update? cc @git-hulk |
Yes, I have simply tested the namespace creation. By the way, I will raise a minor release vote this week to mitigate this CVE issue for users. |
Refer to https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/