chore(deps): bump next to 16.2.11 (9 security advisories) (#8265)

Closes 9 Dependabot alerts (#135-#143) — Next.js 16.0.0..<16.2.11:
SSRF in Server Actions/rewrites, cache confusion, DoS (Server Actions,
Image Optimization SVG, Edge payload), middleware/proxy bypass, and
unauthenticated Server Function endpoint disclosure.

Lockfile bump within the existing ^16.2.6 range (now floored at
^16.2.11); no production code touched.

Co-authored-by: rafaumeu <rafael.zendron22@gmail.com>
This commit is contained in:
Diego Rodrigues de Sa e Souza
2026-07-24 11:43:44 -03:00
committed by GitHub
parent 4e85e3d920
commit 2e355dd0b9
2 changed files with 2 additions and 2 deletions

2
package-lock.json generated
View File

@@ -53,7 +53,7 @@
"material-symbols": "^0.45.2",
"mermaid": "^11.15.0",
"monaco-editor": "^0.56.0",
"next": "^16.2.6",
"next": "^16.2.11",
"next-intl": "^4.12.0",
"next-themes": "^0.4.6",
"node-machine-id": "^1.1.12",

View File

@@ -274,7 +274,7 @@
"material-symbols": "^0.45.2",
"mermaid": "^11.15.0",
"monaco-editor": "^0.56.0",
"next": "^16.2.6",
"next": "^16.2.11",
"next-intl": "^4.12.0",
"next-themes": "^0.4.6",
"node-machine-id": "^1.1.12",