Skip to content

Conversation

@ctate
Copy link
Contributor

@ctate ctate commented Dec 11, 2025

This repository is listed on Vercel Templates.

This PR upgrades dependencies to patch a security vulnerability.

Action required

Please review the changes and run a quick test. If everything looks correct, you can merge this PR.
If you prefer to upgrade manually, feel free to close this and apply your own fix.

Thank you.

This upgrade fixes CVE-2025-55182, a React Server Components RCE vulnerability.
@ctate ctate requested a review from a team as a code owner December 11, 2025 23:54
@vercel
Copy link

vercel bot commented Dec 11, 2025

@ctate is attempting to deploy a commit to the Sanity Sandbox Team on Vercel.

A member of the Team first needs to authorize it.

@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​next@​15.5.7 ⏵ 15.5.883100 +1891 +19870

View full report

Copy link
Contributor

@kenjonespizza kenjonespizza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@vercel
Copy link

vercel bot commented Dec 12, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
nextjs-blog-cms-sanity-v3 Ready Ready Preview Comment Dec 12, 2025 4:25pm

@kenjonespizza kenjonespizza merged commit 616ac6a into sanity-io:main Dec 12, 2025
5 checks passed
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Dec 13, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants