Skip to content

Conversation

@0xtito
Copy link

@0xtito 0xtito commented Feb 10, 2026

16.1.1 -> 16.1.5 (next)
19.2.3 -> 19.2.4 (react/react-dom)

Mentioned in #97

CVEs:
GHSA-5f7q-jpqc-wp7h
GHSA-9g9p-9gw9-jx7f
GHSA-h25m-26qc-wcjf

16.1.1 -> 16.1.5 (next)

19.2.3 -> 19.2.4 (react/react-dom)
Copilot AI review requested due to automatic review settings February 10, 2026 18:53
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the visualizer frontend’s Next.js and React dependencies to patched versions to address the CVEs referenced in Issue #97.

Changes:

  • Bump next from 16.1.1 to 16.1.5
  • Bump react / react-dom from 19.2.3 to 19.2.4
  • Update package-lock.json to reflect the dependency upgrades

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
visualizer/package.json Updates pinned Next.js/React runtime dependency versions to patched releases.
visualizer/package-lock.json Updates resolved versions/hashes for Next.js/React and related Next packages.
Files not reviewed (1)
  • visualizer/package-lock.json: Language not supported
Comments suppressed due to low confidence (1)

visualizer/package-lock.json:1097

  • The lockfile updates @next/env/next to 16.1.5, but @next/eslint-plugin-next (pulled in via eslint-config-next) remains at 16.1.1. After bumping eslint-config-next to the matching Next.js version, regenerate package-lock.json so the plugin/config versions are aligned with the upgraded Next runtime.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant