dependabot[bot] opened a new pull request, #11875:
URL: https://github.com/apache/gravitino/pull/11875

   Bumps 
[eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next)
 from 16.0.6 to 16.2.9.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/vercel/next.js/releases";>eslint-config-next's 
releases</a>.</em></p>
   <blockquote>
   <h2>v16.2.9</h2>
   <p>Empty release to ensure <code>next@latest</code> points at a stable 
release. Next.js only allows publishing with Trusted Publishing enabled. In 
order to fix NPM dist-tags, we have to release a new version. Updating 
dist-tags is not possible with Trusted Publishing.</p>
   <h2>v16.2.8</h2>
   <p>Release with no changes in an attempt to fix <code>next@latest</code> 
pointing at a prerelease version.</p>
   <h2>v16.2.7</h2>
   <blockquote>
   <p>[!NOTE]
   This release is backporting bug fixes. It does <strong>not</strong> include 
all pending features/changes on canary.</p>
   </blockquote>
   <h3>Core Changes</h3>
   <ul>
   <li>Backport documentation fixes for v16.2 (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93804";>#93804</a>)</li>
   <li>[backport] Patch <code>playwright-core</code> to resolve 
<code>_finishedPromise</code> on <code>requestFailed</code> (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93920";>#93920</a>)</li>
   <li>[backport] Fix dev mode hydration failure when page is served from HTTP 
cache (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93492";>#93492</a>)</li>
   <li>[backport] Fix catch-all <code>router.query</code> corruption with 
<code>basePath</code> + <code>rewrites</code> (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93917";>#93917</a>)</li>
   <li>[backport] Encode non-ASCII characters in cache tags at construction (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93918";>#93918</a>)</li>
   <li>[backport] Fix server action forwarding loop with middleware rewrites 
(<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93919";>#93919</a>)</li>
   <li>[backport] Turbopack: switch from base40 to base38 hash encoding (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/93932";>#93932</a>)</li>
   <li>[ci] Disable hanging node 24 typescript tests on 16.2 backport branch 
(<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/94164";>#94164</a>)</li>
   <li>[backport] Fix &quot;type: module&quot; in project dir when using 
standalone or adapters (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/94050";>#94050</a>)</li>
   <li>[backport] Propagate adapter preferred regions (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/94200";>#94200</a>)</li>
   <li>[16.2.x] Don't drop <code>FormData</code> entries (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/94240";>#94240</a>)</li>
   <li>[backport] feat(turbopack): add LocalPathOrProjectPath PostCSS config 
resolution (<a 
href="https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/94284";>#94284</a>)</li>
   </ul>
   <h3>Credits</h3>
   <p>Huge thanks to <a 
href="https://github.com/eps1lon";><code>@​eps1lon</code></a>, <a 
href="https://github.com/icyJoseph";><code>@​icyJoseph</code></a>, <a 
href="https://github.com/unstubbable";><code>@​unstubbable</code></a>, <a 
href="https://github.com/mischnic";><code>@​mischnic</code></a>, <a 
href="https://github.com/bgw";><code>@​bgw</code></a>, <a 
href="https://github.com/timneutkens";><code>@​timneutkens</code></a>, and <a 
href="https://github.com/lukesandberg";><code>@​lukesandberg</code></a> for 
helping!</p>
   <h2>v16.2.6</h2>
   <blockquote>
   <p>[!NOTE]
   This release contains security fixes and backported bug fixes. It does 
<strong>not</strong> include all pending features/changes on canary.</p>
   </blockquote>
   <h3>Security Fixes</h3>
   <p>The following advisories have been addressed:</p>
   <p><strong>High:</strong></p>
   <ul>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-8h8q-6873-q5fj";>GHSA-8h8q-6873-q5fj:
 Denial of Service with Server Components</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f";>GHSA-267c-6grr-h53f:
 Middleware / Proxy bypass in App Router applications via segment-prefetch 
routes</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-26hh-7cqf-hhc6";>GHSA-26hh-7cqf-hhc6:
 Middleware / Proxy bypass in App Router applications via segment-prefetch 
routes - <strong>Incomplete Fix Follow-Up</strong></a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-mg66-mrh9-m8jx";>GHSA-mg66-mrh9-m8jx:
 Denial of Service via connection exhaustion in applications using Cache 
Components</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-492v-c6pp-mqqv";>GHSA-492v-c6pp-mqqv:
 Middleware / Proxy bypass through dynamic route parameter injection</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-c4j6-fc7j-m34r";>GHSA-c4j6-fc7j-m34r:
 Server-side request forgery in applications using WebSocket upgrades</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-36qx-fr4f-26g5";>GHSA-36qx-fr4f-26g5:
 Middleware / Proxy bypass in Pages Router applications using i18n</a></li>
   </ul>
   <p><strong>Moderate:</strong></p>
   <ul>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-ffhc-5mcf-pf4q";>GHSA-ffhc-5mcf-pf4q:
 Cross-site scripting in App Router applications using CSP nonces</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-gx5p-jg67-6x7h";>GHSA-gx5p-jg67-6x7h:
 Cross-site scripting in beforeInteractive scripts with untrusted input</a></li>
   <li><a 
href="https://github.com/vercel/next.js/security/advisories/GHSA-h64f-5h5j-jqjh";>GHSA-h64f-5h5j-jqjh:
 Denial of Service in the Image Optimization API</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/vercel/next.js/commit/f37fad940522e000af5498209fd237d863b4fa16";><code>f37fad9</code></a>
 v16.2.9</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/6f1680448c81904efcd36704edf01a6b7323abbf";><code>6f16804</code></a>
 v16.2.8</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/411c455dcdec630b9e2e83d24e27b0f9e05927b6";><code>411c455</code></a>
 v16.2.7</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/ee6e79b1792a4d401ddf2480f40a83549fe8e722";><code>ee6e79b</code></a>
 v16.2.6</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/766148f9cd48c0e218acafcd0f15defc14871bf4";><code>766148f</code></a>
 v16.2.5</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/2275bd8598c88e8652d1271e74bcf972f72f4f38";><code>2275bd8</code></a>
 v16.2.4</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/d5f649b2f4affdad1009cb178c1e3b37f4f1ad3f";><code>d5f649b</code></a>
 v16.2.3</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/52faae3d94641584e13691238df5be158d0f00fb";><code>52faae3</code></a>
 v16.2.2</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/ed7d2cef246dcb3e2955c018fd8b2027e0ff8eed";><code>ed7d2ce</code></a>
 v16.2.1</li>
   <li><a 
href="https://github.com/vercel/next.js/commit/c5c94dffbf084e66b172a9c6ff23d80c24973764";><code>c5c94df</code></a>
 v16.2.0</li>
   <li>Additional commits viewable in <a 
href="https://github.com/vercel/next.js/commits/v16.2.9/packages/eslint-config-next";>compare
 view</a></li>
   </ul>
   </details>
   <details>
   <summary>Maintainer changes</summary>
   <p>This version was pushed to npm by <a 
href="https://www.npmjs.com/~GitHub%20Actions";>GitHub Actions</a>, a new 
releaser for eslint-config-next since your current version.</p>
   </details>
   <br />
   
   <details>
   <summary>Most Recent Ignore Conditions Applied to This Pull Request</summary>
   
   | Dependency Name | Ignore Conditions |
   | --- | --- |
   | eslint-config-next | [>= 15.a, < 16] |
   | eslint-config-next | [>= 14.2.a, < 14.3] |
   </details>
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=eslint-config-next&package-manager=npm_and_yarn&previous-version=16.0.6&new-version=16.2.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to