Skip to content

Commit 7c2ffdc

Browse files
Sync Collecting Fix Commits: Wed Aug 26 17:12:48 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent dde5cb2 commit 7c2ffdc

5 files changed

Lines changed: 117 additions & 10 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 101 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,107 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-2WXC-X7RJ-HG8F": {
5+
"1819bf753afbd5394fdcf28a0d83898deb67c2c0": "Publish Advisories\n\nGHSA-2wxc-x7rj-hg8f\nGHSA-qr67-gv47-xwwh"
6+
},
7+
"GHSA-QR67-GV47-XWWH": {
8+
"1819bf753afbd5394fdcf28a0d83898deb67c2c0": "Publish Advisories\n\nGHSA-2wxc-x7rj-hg8f\nGHSA-qr67-gv47-xwwh"
9+
},
10+
"GHSA-JRW6-7X4Q-W25J": {
11+
"f7584978eaf2432555e8ed5baf7f946162aeaff1": "Publish Advisories\n\nGHSA-jrw6-7x4q-w25j\nGHSA-p46m-g734-vpc4"
12+
},
13+
"GHSA-P46M-G734-VPC4": {
14+
"f7584978eaf2432555e8ed5baf7f946162aeaff1": "Publish Advisories\n\nGHSA-jrw6-7x4q-w25j\nGHSA-p46m-g734-vpc4"
15+
},
16+
"GHSA-W93Q-CQ9W-58P7": {
17+
"c02e9c72636204dde9927da3454e365a7582ccc2": "Publish GHSA-w93q-cq9w-58p7"
18+
},
19+
"GHSA-M5VH-3FW5-5WGH": {
20+
"5a04b8336588352156b480dc79d6c2aeb6ce28e9": "Publish Advisories\n\nGHSA-m5vh-3fw5-5wgh\nGHSA-w5fv-7x5q-g8qp\nGHSA-m5vh-3fw5-5wgh",
21+
"eee2e1012fa1e545369197fcb83f654be2bb6bb6": "Merge pull request #8643 from oscerd/oscerd-GHSA-m5vh-3fw5-5wgh",
22+
"8391dec96c289320011f7fcc0f64e46d125f7f2c": "[GHSA-m5vh-3fw5-5wgh] JmsBinding.extractBodyFromJms() in camel-jms, and the equ...\n\nSigned-off-by: Andrea Cosentino <ancosen@gmail.com>"
23+
},
24+
"GHSA-W5FV-7X5Q-G8QP": {
25+
"5a04b8336588352156b480dc79d6c2aeb6ce28e9": "Publish Advisories\n\nGHSA-m5vh-3fw5-5wgh\nGHSA-w5fv-7x5q-g8qp\nGHSA-m5vh-3fw5-5wgh"
26+
},
27+
"GHSA-6QW3-4796-5984": {
28+
"bea96aded61ab43aa6ac3df9170cc73bd4126209": "Publish Advisories\n\nGHSA-6qw3-4796-5984\nGHSA-6qw3-4796-5984",
29+
"6bc8047ee28d4397a65f09371b9912ce06d3e22c": "Merge pull request #8642 from oscerd/oscerd-GHSA-6qw3-4796-5984",
30+
"3452c973551680aec273dc504374efcf84d4f7af": "[GHSA-6qw3-4796-5984] Deserialization of Untrusted Data vulnerability in Apache...\n\nSigned-off-by: Andrea Cosentino <ancosen@gmail.com>"
31+
},
32+
"GHSA-8H6P-JVHF-9HCR": {
33+
"011c24bbc1d371822faa474ef6e090cf51d3c84d": "Publish Advisories\n\nGHSA-8h6p-jvhf-9hcr\nGHSA-8h6p-jvhf-9hcr",
34+
"cdf94b1bf146a258727f87430e3883ffdaf4031a": "Merge pull request #8644 from oscerd/oscerd-GHSA-8h6p-jvhf-9hcr",
35+
"0176e36ca74687f4d6becc159fe0fc7bb99a92a8": "[GHSA-8h6p-jvhf-9hcr] Deserialization of Untrusted Data vulnerability in Apache...\n\nSigned-off-by: Andrea Cosentino <ancosen@gmail.com>"
36+
},
37+
"GHSA-68MC-H6H8-79WJ": {
38+
"432a78a67ae577e2a6610af5a17e55439bf60c65": "Publish Advisories\n\nGHSA-68mc-h6h8-79wj\nGHSA-cmwh-w62w-r2mf\nGHSA-g743-m6x3-v6wm\nGHSA-cmwh-w62w-r2mf"
39+
},
40+
"GHSA-CMWH-W62W-R2MF": {
41+
"432a78a67ae577e2a6610af5a17e55439bf60c65": "Publish Advisories\n\nGHSA-68mc-h6h8-79wj\nGHSA-cmwh-w62w-r2mf\nGHSA-g743-m6x3-v6wm\nGHSA-cmwh-w62w-r2mf"
42+
},
43+
"GHSA-G743-M6X3-V6WM": {
44+
"432a78a67ae577e2a6610af5a17e55439bf60c65": "Publish Advisories\n\nGHSA-68mc-h6h8-79wj\nGHSA-cmwh-w62w-r2mf\nGHSA-g743-m6x3-v6wm\nGHSA-cmwh-w62w-r2mf"
45+
},
46+
"GHSA-26M2-9G2Q-V45Q": {
47+
"6cc12c1e4e8bc6b3e59e8ef2bb00eda58eb4a859": "Publish GHSA-26m2-9g2q-v45q"
48+
},
49+
"GHSA-7H7J-7VWP-CWFG": {
50+
"e6ca69b79bc085ba23157a22df85a782ca78abaa": "Publish GHSA-7h7j-7vwp-cwfg"
51+
},
52+
"GHSA-X287-5C68-36WP": {
53+
"5ea4ade0f6a9ee3b697fb29781584b5260b57a77": "Publish GHSA-x287-5c68-36wp"
54+
},
55+
"GHSA-W2V8-8Q6C-3RHR": {
56+
"4bbd1a17d1ff2338ad590d9435a64dc8206ef452": "Publish Advisories\n\nGHSA-w2v8-8q6c-3rhr\nGHSA-93qj-5q5v-3c2h\nGHSA-m452-q8c9-rg2f",
57+
"f59d3e80e1680a0d12759266ab892b2f02a41a55": "Merge pull request #8640 from github/oscerd-GHSA-w2v8-8q6c-3rhr",
58+
"7c1569b875271d9c6dac1fcb5426ff14d4a38a83": "Improve GHSA-w2v8-8q6c-3rhr"
59+
},
60+
"GHSA-93QJ-5Q5V-3C2H": {
61+
"4bbd1a17d1ff2338ad590d9435a64dc8206ef452": "Publish Advisories\n\nGHSA-w2v8-8q6c-3rhr\nGHSA-93qj-5q5v-3c2h\nGHSA-m452-q8c9-rg2f"
62+
},
63+
"GHSA-M452-Q8C9-RG2F": {
64+
"4bbd1a17d1ff2338ad590d9435a64dc8206ef452": "Publish Advisories\n\nGHSA-w2v8-8q6c-3rhr\nGHSA-93qj-5q5v-3c2h\nGHSA-m452-q8c9-rg2f"
65+
},
66+
"GHSA-RPV3-6645-2VQC": {
67+
"01d1d6f6f44f479de1370fe30d29d717d97f35b4": "Publish Advisories\n\nGHSA-rpv3-6645-2vqc\nGHSA-3p27-qvp9-27qf",
68+
"34e451ef46ec7415ecdcb167c96290b90a8b02ef": "Merge pull request #8641 from oscerd/oscerd-GHSA-rpv3-6645-2vqc",
69+
"8d731c0569bb10844e493f67c172bb554ce27503": "[GHSA-rpv3-6645-2vqc] Improper Neutralization of Argument Delimiters in a Comma...\n\nSigned-off-by: Andrea Cosentino <ancosen@gmail.com>"
70+
},
71+
"GHSA-3P27-QVP9-27QF": {
72+
"01d1d6f6f44f479de1370fe30d29d717d97f35b4": "Publish Advisories\n\nGHSA-rpv3-6645-2vqc\nGHSA-3p27-qvp9-27qf",
73+
"343a02609d5b4822922972e271960eecb71e396b": "Publish Advisories\n\nGHSA-3p27-qvp9-27qf\nGHSA-8h6h-x5pq-56fq"
74+
},
75+
"GHSA-8H6H-X5PQ-56FQ": {
76+
"343a02609d5b4822922972e271960eecb71e396b": "Publish Advisories\n\nGHSA-3p27-qvp9-27qf\nGHSA-8h6h-x5pq-56fq"
77+
},
78+
"GHSA-F63G-88CJ-HJF9": {
79+
"7bea8587a2feea42130bb8aa15162110c1cec54c": "Publish GHSA-f63g-88cj-hjf9"
80+
},
81+
"GHSA-79GF-7FRW-68M9": {
82+
"977458b93af3b7075483e4599f1f3b4f3197e113": "Publish GHSA-79gf-7frw-68m9"
83+
},
84+
"GHSA-MV8M-V9V6-5F94": {
85+
"792618256641ce003debd7465b5d0aa17c6d76ae": "Publish GHSA-mv8m-v9v6-5f94"
86+
},
87+
"GHSA-6753-GR46-6WPR": {
88+
"287c6f753d3ad4805b4fcb54a587bf5e641feeed": "Publish GHSA-6753-gr46-6wpr"
89+
},
90+
"GHSA-VMM3-XGCX-67HM": {
91+
"cb903af0cbf5f801e45e51732c45faea75d2ad78": "Publish GHSA-vmm3-xgcx-67hm"
92+
},
93+
"GHSA-6X9P-4R67-5GJX": {
94+
"a5406a1b47fd2f3ddf7b7a6c059df41ed49a2416": "Publish GHSA-6x9p-4r67-5gjx"
95+
},
96+
"GHSA-6WVW-VRW4-363W": {
97+
"d54bfa4292d4b00d2cb55b39d93815b410f5f5b9": "Improve GHSA-6wvw-vrw4-363w",
98+
"d0f0467d4afab07aec82a755fcdde993c7f43335": "Publish Advisories\n\nGHSA-33j8-j763-4fv5\nGHSA-3vx2-vqx8-jxfg\nGHSA-83r6-96m8-r52p\nGHSA-93g8-qqv3-mrx8\nGHSA-qp3f-rvj8-46c8\nGHSA-xf62-wr5p-5p95\nGHSA-2p39-2jf3-fv2q\nGHSA-6wvw-vrw4-363w\nGHSA-8fxq-53rx-ph5f\nGHSA-h58c-xccx-75m3\nGHSA-jgvr-6x5w-hx5w\nGHSA-mc9m-6fm9-pghc\nGHSA-mq36-523m-x7vv"
99+
},
100+
"GHSA-GJRP-XGMH-X9QQ": {
101+
"fc6f8c124e81ec21078c55bad50c43a255f28d18": "Improve GHSA-gjrp-xgmh-x9qq",
102+
"333742e9cacaa43f365b92429bc394e4078ab864": "Publish Advisories\n\nGHSA-2w69-qvjg-hvjx\nGHSA-3cgp-3xvw-98x8\nGHSA-4f6g-68pf-7vhv\nGHSA-4xc4-762w-m6cg\nGHSA-5fp7-g646-ccf4\nGHSA-78h3-63c4-5fqc\nGHSA-8v8x-cx79-35w7\nGHSA-9583-h5hc-x8cw\nGHSA-9jcx-v3wj-wh4m\nGHSA-9xg7-mwmp-xmjx\nGHSA-gjrp-xgmh-x9qq\nGHSA-h5cw-625j-3rxh\nGHSA-pcwc-3fw3-8cqv\nGHSA-wfq2-52f7-7qvj",
103+
"16e70357e490838f1c9a4137097f80225a4c8f3d": "Publish Advisories\n\nGHSA-54m3-5fxr-2f3j\nGHSA-6jm8-x3g6-r33j\nGHSA-87hc-h4r5-73f7\nGHSA-g268-72p7-9j6j\nGHSA-gjrp-xgmh-x9qq\nGHSA-rjf8-2wcw-f6mp"
104+
},
4105
"GHSA-65R4-943X-97JJ": {
5106
"fdfded361988a00fcc130cad2aa7aad11362362c": "Improve GHSA-65r4-943x-97jj"
6107
},
@@ -1163,9 +1264,6 @@
11631264
"GHSA-2P39-2JF3-FV2Q": {
11641265
"d0f0467d4afab07aec82a755fcdde993c7f43335": "Publish Advisories\n\nGHSA-33j8-j763-4fv5\nGHSA-3vx2-vqx8-jxfg\nGHSA-83r6-96m8-r52p\nGHSA-93g8-qqv3-mrx8\nGHSA-qp3f-rvj8-46c8\nGHSA-xf62-wr5p-5p95\nGHSA-2p39-2jf3-fv2q\nGHSA-6wvw-vrw4-363w\nGHSA-8fxq-53rx-ph5f\nGHSA-h58c-xccx-75m3\nGHSA-jgvr-6x5w-hx5w\nGHSA-mc9m-6fm9-pghc\nGHSA-mq36-523m-x7vv"
11651266
},
1166-
"GHSA-6WVW-VRW4-363W": {
1167-
"d0f0467d4afab07aec82a755fcdde993c7f43335": "Publish Advisories\n\nGHSA-33j8-j763-4fv5\nGHSA-3vx2-vqx8-jxfg\nGHSA-83r6-96m8-r52p\nGHSA-93g8-qqv3-mrx8\nGHSA-qp3f-rvj8-46c8\nGHSA-xf62-wr5p-5p95\nGHSA-2p39-2jf3-fv2q\nGHSA-6wvw-vrw4-363w\nGHSA-8fxq-53rx-ph5f\nGHSA-h58c-xccx-75m3\nGHSA-jgvr-6x5w-hx5w\nGHSA-mc9m-6fm9-pghc\nGHSA-mq36-523m-x7vv"
1168-
},
11691267
"GHSA-8FXQ-53RX-PH5F": {
11701268
"d0f0467d4afab07aec82a755fcdde993c7f43335": "Publish Advisories\n\nGHSA-33j8-j763-4fv5\nGHSA-3vx2-vqx8-jxfg\nGHSA-83r6-96m8-r52p\nGHSA-93g8-qqv3-mrx8\nGHSA-qp3f-rvj8-46c8\nGHSA-xf62-wr5p-5p95\nGHSA-2p39-2jf3-fv2q\nGHSA-6wvw-vrw4-363w\nGHSA-8fxq-53rx-ph5f\nGHSA-h58c-xccx-75m3\nGHSA-jgvr-6x5w-hx5w\nGHSA-mc9m-6fm9-pghc\nGHSA-mq36-523m-x7vv"
11711269
},
@@ -12155,9 +12253,6 @@
1215512253
"GHSA-PJHX-3C3W-9V23": {
1215612254
"0425e75a5104a1ed295759ddc5ba8e6100f8009e": "Publish Advisories\n\nGHSA-4hhg-8ghq-vwq6\nGHSA-4vj7-5mj6-jm8m\nGHSA-pjhx-3c3w-9v23"
1215712255
},
12158-
"GHSA-W2V8-8Q6C-3RHR": {
12159-
"7c1569b875271d9c6dac1fcb5426ff14d4a38a83": "Improve GHSA-w2v8-8q6c-3rhr"
12160-
},
1216112256
"GHSA-8F88-W9GQ-227V": {
1216212257
"7438d5a164c8e831634d0100f241f86e8bcb484b": "Publish Advisories\n\nGHSA-p2wm-69qx-x25w\nGHSA-8f88-w9gq-227v\nGHSA-9c82-3f2r-v942\nGHSA-f9rq-5867-x4mq\nGHSA-ghgx-h467-6r25"
1216312258
},
@@ -58854,10 +58949,6 @@
5885458949
"333742e9cacaa43f365b92429bc394e4078ab864": "Publish Advisories\n\nGHSA-2w69-qvjg-hvjx\nGHSA-3cgp-3xvw-98x8\nGHSA-4f6g-68pf-7vhv\nGHSA-4xc4-762w-m6cg\nGHSA-5fp7-g646-ccf4\nGHSA-78h3-63c4-5fqc\nGHSA-8v8x-cx79-35w7\nGHSA-9583-h5hc-x8cw\nGHSA-9jcx-v3wj-wh4m\nGHSA-9xg7-mwmp-xmjx\nGHSA-gjrp-xgmh-x9qq\nGHSA-h5cw-625j-3rxh\nGHSA-pcwc-3fw3-8cqv\nGHSA-wfq2-52f7-7qvj",
5885558950
"3240cf4f6c358cf8ffdcfcd58ef805dfafda097a": "Publish Advisories\n\nGHSA-mrj3-f2h4-7w45\nGHSA-g9jg-w8vm-g96v\nGHSA-5j4h-4f72-qpm6\nGHSA-6h7w-v2xr-mqvw\nGHSA-9xg7-mwmp-xmjx\nGHSA-mqhg-v22x-pqj8\nGHSA-vmc4-9828-r48r"
5885658951
},
58857-
"GHSA-GJRP-XGMH-X9QQ": {
58858-
"333742e9cacaa43f365b92429bc394e4078ab864": "Publish Advisories\n\nGHSA-2w69-qvjg-hvjx\nGHSA-3cgp-3xvw-98x8\nGHSA-4f6g-68pf-7vhv\nGHSA-4xc4-762w-m6cg\nGHSA-5fp7-g646-ccf4\nGHSA-78h3-63c4-5fqc\nGHSA-8v8x-cx79-35w7\nGHSA-9583-h5hc-x8cw\nGHSA-9jcx-v3wj-wh4m\nGHSA-9xg7-mwmp-xmjx\nGHSA-gjrp-xgmh-x9qq\nGHSA-h5cw-625j-3rxh\nGHSA-pcwc-3fw3-8cqv\nGHSA-wfq2-52f7-7qvj",
58859-
"16e70357e490838f1c9a4137097f80225a4c8f3d": "Publish Advisories\n\nGHSA-54m3-5fxr-2f3j\nGHSA-6jm8-x3g6-r33j\nGHSA-87hc-h4r5-73f7\nGHSA-g268-72p7-9j6j\nGHSA-gjrp-xgmh-x9qq\nGHSA-rjf8-2wcw-f6mp"
58860-
},
5886158952
"GHSA-WFQ2-52F7-7QVJ": {
5886258953
"333742e9cacaa43f365b92429bc394e4078ab864": "Publish Advisories\n\nGHSA-2w69-qvjg-hvjx\nGHSA-3cgp-3xvw-98x8\nGHSA-4f6g-68pf-7vhv\nGHSA-4xc4-762w-m6cg\nGHSA-5fp7-g646-ccf4\nGHSA-78h3-63c4-5fqc\nGHSA-8v8x-cx79-35w7\nGHSA-9583-h5hc-x8cw\nGHSA-9jcx-v3wj-wh4m\nGHSA-9xg7-mwmp-xmjx\nGHSA-gjrp-xgmh-x9qq\nGHSA-h5cw-625j-3rxh\nGHSA-pcwc-3fw3-8cqv\nGHSA-wfq2-52f7-7qvj",
5886358954
"1f72a3d670630679b2c32184e413fe161f937b5c": "Publish GHSA-wfq2-52f7-7qvj"

data/fix-commits/buildkit-34c30119.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/moby/buildkit",
33
"vulnerabilities": {
4+
"GHSA-2V4P-QF9Q-27WJ": {
5+
"964cf3d104ed8178991e0adf4964b6ed367d3279": "vendor: google.golang.org/grpc v1.83.2\n\ncontains a fix for [GHSA-2v4p-qf9q-27wj]\n\nfull diff: https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2\n\n[GHSA-2v4p-qf9q-27wj]: https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
6+
},
47
"CVE-2026-47262": {
58
"64dc21e3f749ddb0ca56335708a96cc8e4257681": "vendor: github.com/moby/sys/user v0.4.1\n\n- user: prevent possible DoS via unbounded parsing of user and group\n database files in GHSA-mjcv-p78q-w5fw. This fixes a similar issue\n as CVE-2026-47262 in containerd.\n- user: prevent falling back to looking up numeric usernames\n Improve handling of numeric user/group to prevent looking up numeric\n values as usernames. This fixes a similar issue as [CVE-2026-46680] in\n containerd.\n- user: update minimum go version to go1.18\n- assorted testing and linting fixes.\n\n[CVE-2026-46680]: https://github.com/advisories/GHSA-fqw6-gf59-qr4w\n\nfull diff: https://github.com/moby/sys/compare/user/v0.4.0...user/v0.4.1\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>",
69
"ac1270b48fc4a36ec91ea5c2df702d7a7d741aba": "Dockerfile: update containerd v2.2.5, v2.1.9, v1.7.33\n\n- full diff: https://github.com/containerd/containerd/compare/v2.2.4...v2.2.5\n- release notes: https://github.com/containerd/containerd/releases/tag/v2.2.5\n\nThe fifth patch release for containerd 2.2 contains various fixes\nand updates including security patches.\n\n- CVE-2026-50195 / [GHSA-cvxm-645q-p574] CRI: checkpoint import allows local image tag poisoning\n- CVE-2026-53488 / [GHSA-xhf5-7wjv-pqxp] CRI: image-config LABEL flows to host-root command execution from an image pull\n- CVE-2026-53492 / [GHSA-33vj-92qq-66hc] CRI: CDI annotation smuggling during CRI checkpoint restore\n- CVE-2026-53489 / [GHSA-rgh6-rfwx-v388] CRI: Arbitrary host file read via symlink following in CRI checkpoint restore\n- CVE-2026-47262 / [GHSA-jpcc-p29g-p8mq] containerd image-triggered runtime DoS via unbounded group parsing\n\n[GHSA-cvxm-645q-p574]: https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574\n[GHSA-xhf5-7wjv-pqxp]: https://github.com/containerd/containerd/security/advisories/GHSA-xhf5-7wjv-pqxp\n[GHSA-33vj-92qq-66hc]: https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc\n[GHSA-rgh6-rfwx-v388]: https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388\n[GHSA-jpcc-p29g-p8mq]: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>",

data/fix-commits/next.js-dcb792d7.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/vercel/next.js",
33
"vulnerabilities": {
4+
"GHSA-G89C-P67H-R497": {
5+
"a745b3a3845acb5da35dc7e4ac79ff505c6b9b5d": "Bump sharp to ^0.35.4\n\nsharp 0.35.4 ships sharp-libvips 1.3.3 with libheif 1.23.2, which fixes\ntwo critical vulnerabilities in AVIF decoding (GHSA-g89c-p67h-r497 and\nGHSA-2jg2-4ch7-h545). Raising the floor from ^0.35.3 to ^0.35.4 ensures\nfresh installs pick up the fix.\n\nBecause 0.35.4 was published less than 48 hours ago, it falls inside\nthis repo's `minimumReleaseAge` window. pnpm aborts the whole install\nwith ERR_PNPM_NO_MATURE_MATCHING_VERSION when an optional dependency\nhas no in-range release older than the gate: optional dependencies are\nnot skipped, and the gate also covers the `@img/sharp-*` binary packages\npublished alongside sharp. `sharp@0.35.4` and every `@img/sharp-*` and\n`@img/sharp-libvips-*` package at its exact published version are added\nto `minimumReleaseAgeExclude` so this repo and the isolated test\ninstalls inheriting its settings can resolve the fixed version. The\nexemptions name exact versions, so they do not weaken the age gate for\nfuture sharp releases, and they can be removed once 0.35.4 is older\nthan 48 hours."
6+
},
7+
"GHSA-2JG2-4CH7-H545": {
8+
"a745b3a3845acb5da35dc7e4ac79ff505c6b9b5d": "Bump sharp to ^0.35.4\n\nsharp 0.35.4 ships sharp-libvips 1.3.3 with libheif 1.23.2, which fixes\ntwo critical vulnerabilities in AVIF decoding (GHSA-g89c-p67h-r497 and\nGHSA-2jg2-4ch7-h545). Raising the floor from ^0.35.3 to ^0.35.4 ensures\nfresh installs pick up the fix.\n\nBecause 0.35.4 was published less than 48 hours ago, it falls inside\nthis repo's `minimumReleaseAge` window. pnpm aborts the whole install\nwith ERR_PNPM_NO_MATURE_MATCHING_VERSION when an optional dependency\nhas no in-range release older than the gate: optional dependencies are\nnot skipped, and the gate also covers the `@img/sharp-*` binary packages\npublished alongside sharp. `sharp@0.35.4` and every `@img/sharp-*` and\n`@img/sharp-libvips-*` package at its exact published version are added\nto `minimumReleaseAgeExclude` so this repo and the isolated test\ninstalls inheriting its settings can resolve the fixed version. The\nexemptions name exact versions, so they do not weaken the age gate for\nfuture sharp releases, and they can be removed once 0.35.4 is older\nthan 48 hours."
9+
},
410
"GHSA-6G55-P6WH-862Q": {
511
"470ec9acf7f1d3d0719b8e2423e7527f91743c8e": "Bump postcss to 8.5.23 (#96107)\n\nNote that https://github.com/advisories/GHSA-6g55-p6wh-862q does not\naffect Next.js users unless they build from untrusted source code (which\nwould have more severe security implications). We're merging this to\nreduce noise from security scanners.\n\n- 8.5.21 is 50h+ old so it can be installed\n- 8.5.22 is still under 48h - valid at 2026-07-24 08:48:15 UTC \n\nCloses: https://github.com/vercel/next.js/issues/96349\n\nCo-authored-by: Joseph <joseph.chamochumbi@vercel.com>",
612
"5cdcbbb05be0abc21afcb8d5346cc12d854be537": "Bump postcss to 8.5.23 (#96107)\n\nNote that https://github.com/advisories/GHSA-6g55-p6wh-862q does not\naffect Next.js users unless they build from untrusted source code (which\nwould have more severe security implications). We're merging this to\nreduce noise from security scanners.\n\n- 8.5.21 is 50h+ old so it can be installed\n- 8.5.22 is still under 48h - valid at 2026-07-24 08:48:15 UTC \n\nCloses: https://github.com/vercel/next.js/issues/96349"

0 commit comments

Comments
 (0)