Skip to content

chore(deps)(deps): bump next from 15.5.16 to 15.5.18#294

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot-npm_and_yarn-next-15.5.18
Closed

chore(deps)(deps): bump next from 15.5.16 to 15.5.18#294
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot-npm_and_yarn-next-15.5.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 13, 2026

Copy link
Copy Markdown
Contributor

Bumps next from 15.5.16 to 15.5.18.

Release notes

Sourced from next's releases.

v15.5.18

This release contains security fixes for the following advisories:

High:

Moderate:

Low:

Commits
  • 9ff92ce v15.5.18
  • 00ebe23 [backport] Disable build caches for production/staging/force-preview deploys ...
  • 62c97ab v15.5.17
  • 423623a Turbopack: Match proxy matchers with webpack implementation (#93594)
  • fa78739 Turbopack: Fix middleware matcher suffix (#93590)
  • 36e62c6 [backport] Turbopack: more strict vergen setup (#93588)
  • 36589b5 [backport][test] Pin package manager to patch versions (#93596)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [next](https://github.com/vercel/next.js) from 15.5.16 to 15.5.18.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](vercel/next.js@v15.5.16...v15.5.18)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 15.5.18
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 13, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: area:libs. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions github-actions Bot mentioned this pull request May 13, 2026
@github-actions

Copy link
Copy Markdown

Repo Manager PR Triage

Risk level: High

Applied or recommended labels:

  • area:frontend
  • area:security
  • kind:chore
  • priority:high
  • status:ready

Applied or recommended milestone:

  • none

Related issues:

  • No strong issue match found from title/body/scope.

Required checks:

  • CI for dependency update (install/build/test) should pass before merge.

Recommended reviewers / owner areas:

  • Frontend and security maintainers.

Notes:

  • This PR upgrades next to a security-fix release (15.5.18) and updates lockfile state.
  • Dependabot reported a repository label mismatch (area:libs not found). A repo-manager report issue was opened for maintainers to fix label sync/config consistency.

Generated by Helix AI Repo Manager for issue #294 ·

@github-actions

This comment has been minimized.

@github-actions

Copy link
Copy Markdown

Dependency Manager Security Review

This appears to be a security-related dependency update for next in apps/frontend plus lockfile regeneration.

Risk level: High

Recommended next action:

  • Review the Next.js advisories/changelog impact for your app routes and middleware usage.
  • Run full CI/security validation and proceed once required checks are green.
  • Keep this PR out of auto-merge until checks are confirmed and maintainer review is complete.

Auto-merge was not enabled for this PR.

Note

🔒 Integrity filter blocked 78 items

The following items were blocked because they don't meet the GitHub integrity level.

To allow these resources, lower min-integrity in your GitHub frontmatter:

tools:
  github:
    min-integrity: approved  # merged | approved | unapproved | none

Generated by Helix AI Dependency Manager ·

@dependabot @github

dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #314.

@dependabot dependabot Bot closed this Jun 2, 2026
@dependabot dependabot Bot deleted the dependabot-npm_and_yarn-next-15.5.18 branch June 2, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant