next.js
c692e952 - Bump next in upgrade eval fixtures for CVE-2026-94483 (#99838)

Commit
3 days ago
Bump next in upgrade eval fixtures for CVE-2026-94483 (#99838) ## Summary Bumps `next` in three upgrade eval fixtures that were pinned to versions affected by CVE-2026-94483 (Image Optimization SSRF via allow-listed remote patterns; fixed in 16.3.8): - `future-cache-components-nudge`: 16.3.5 → 16.4.0 - `future-cache-components-same-version`: 16.3.5 → 16.4.0 - `latest-same-major`: 16.2.12 → 16.3.8 A few things needed to be updated to match - `latest/setup.ts` and `future/setup.ts` mock `registry.npmjs.org/next/latest` with a hardcoded `target`. That target is now 16.4.0 (the current `latest`), so the same-version scenarios still sit on "latest" and the same-major scenario still has a newer target in the same major. - `latest-same-major` uses 16.3.8 rather than 16.4.0 because it has to start below the target in the same major. 16.3.8 is the oldest patched release; there is no patched 16.2.x. - The `EVAL.ts` exact-version assertions are updated to match. The `latest-cross-major`, `latest-nudge` and `future-cache-components` scenarios now also upgrade to 16.4.0. Their starting versions are unchanged. Fixes VULN-16485 Fixes VULN-16486 Fixes VULN-16487 <!-- NEXT_JS_LLM -->
Author
Parents
Loading