Skip to content

Upgrade to NextJS 11 to fix CVEs #189

Merged
EnriqueL8 merged 5 commits into
hyperledger:mainfrom
SamMayWork:fix-cves
Dec 11, 2025
Merged

Upgrade to NextJS 11 to fix CVEs #189
EnriqueL8 merged 5 commits into
hyperledger:mainfrom
SamMayWork:fix-cves

Conversation

@SamMayWork

Copy link
Copy Markdown
Contributor

Noticed that we're quite behind on CVEs here so proposing and upgrade to the predominantly the NestJS libraries to get us on the latest versions and get us CVE-free (NestJS 11)

Signed-off-by: SamMayWork <sam.may@kaleido.io>
Signed-off-by: SamMayWork <sam.may@kaleido.io>
@SamMayWork SamMayWork requested a review from a team as a code owner December 11, 2025 12:14
Signed-off-by: SamMayWork <sam.may@kaleido.io>
@SamMayWork

Copy link
Copy Markdown
Contributor Author

Note: I've removed the specific named versions of jq/curl introduced by this PR #176 it looks like it was originally done for dependency conflicts but that appears to no longer be an issue

@EnriqueL8 EnriqueL8 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @SamMayWork !

As you mention this is quite a big upgrade of major version, so doing some E2E testing would be good

Do you mind linking which CVEs exactly this is fixing if you have that information handy?

Comment thread Dockerfile
Comment thread package.json
@SamMayWork

Copy link
Copy Markdown
Contributor Author

@EnriqueL8 EnriqueL8 changed the title [cve] Updates to resolve multiple CVEs (NestJS upgrade) Upgrade to NextJS 11 to fix CVEs Dec 11, 2025
Signed-off-by: SamMayWork <sam.may@kaleido.io>
Signed-off-by: SamMayWork <sam.may@kaleido.io>
Comment thread package.json

@EnriqueL8 EnriqueL8 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the great work here @SamMayWork - testing and explaining why the Nest 11 upgrade is safe and fixes loads of CVEs 🙇🏼

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants