(CVE-2025-55182)#460
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
WalkthroughDependency version updates across the monorepo: React and React-DOM upgraded from 19.0.0 to 19.2.1; Next.js packages updated from 15.3.2 to 15.3.6; internal packages changed from exact to caret version constraints; pnpm.overrides added to the root package.json. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~5 minutes
Possibly related PRs
Poem
Pre-merge checks and finishing touches❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✨ Finishing touches🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: CodeRabbit UI Review profile: CHILL Plan: Pro ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (13)
🧰 Additional context used📓 Path-based instructions (1)package.json📄 CodeRabbit inference engine (AGENTS.md)
Files:
🧠 Learnings (8)📓 Common learnings📚 Learning: 2025-12-01T00:21:48.564ZApplied to files:
📚 Learning: 2025-12-01T00:21:48.564ZApplied to files:
📚 Learning: 2025-12-01T00:21:48.564ZApplied to files:
📚 Learning: 2025-12-01T00:21:48.564ZApplied to files:
📚 Learning: 2025-12-01T00:22:41.045ZApplied to files:
📚 Learning: 2025-12-01T00:21:48.564ZApplied to files:
📚 Learning: 2025-12-01T00:22:19.083ZApplied to files:
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
🔇 Additional comments (13)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
fix CVE-2025-55182
Note
Upgrade monorepo to React 19.2.1 and Next 15.3.6 (with aligned tooling and lockfile updates) across apps and internal packages.
react/react-domto19.2.1andnextto15.3.6; aligneslint-config-nextto15.3.6and add pnpm overrides.apps/backgrounds,apps/viewer: upgradenext,react,react-dom,eslint-config-next.apps/blog,apps/docs: upgradereact,react-dom.desktop: upgradereact,react-dom.editor: upgradenext,react,react-domand related libs to compatible versions.reactto^19.0.0and keep peer ranges supporting^18 || ^19.Written by Cursor Bugbot for commit 0b78889. This will update automatically on new commits. Configure here.
Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.