Skip to content

fix: patch open Dependabot security alerts - #1

Open
jseramn wants to merge 1 commit into
mainfrom
security/patch-dependabot-alerts
Open

fix: patch open Dependabot security alerts#1
jseramn wants to merge 1 commit into
mainfrom
security/patch-dependabot-alerts

Conversation

@jseramn

@jseramn jseramn commented Jul 23, 2026

Copy link
Copy Markdown
Owner

Summary

  • Upgrade next from 14.2.18 → 15.5.21 to clear Critical/High Dependabot alerts (no safe 14.x backport for several advisories).
  • Bump postcss and add npm overrides for nested postcss/sharp.
  • Keep GitHub Pages static export working (images.unoptimized, typed carousel callback, outputFileTracingRoot).

Test plan

  • npm audit → 0 vulnerabilities
  • npm run build succeeds with GITHUB_PAGES=true
  • Confirm Dependabot alerts on main drop to 0 after merge

Made with Cursor

Upgrade Next.js and force patched postcss/sharp so open npm advisories clear while keeping the Pages export build working.

Co-authored-by: Cursor <cursoragent@cursor.com>
@netlify

netlify Bot commented Jul 23, 2026

Copy link
Copy Markdown

Deploy Preview for misairpodscartagena ready!

Name Link
🔨 Latest commit c9da319
🔍 Latest deploy log https://app.netlify.com/projects/misairpodscartagena/deploys/6a627bf66c8fec0008b687e8
😎 Deploy Preview https://deploy-preview-1--misairpodscartagena.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant