Skip to content

Commit e7e6450

Browse files
committed
fix(deps): patch next-mdx-remote and opentelemetry CVEs
- bump next-mdx-remote 5.0.0 → 6.0.0 (GHSA-g4xw-jxrg-5f6m / CVE-2026-0969, arbitrary code execution in MDX serialize) - bump @opentelemetry/sdk-node and exporter-trace-otlp-http 0.200.0 → 0.217.0 (GHSA-q7rr-3cgh-j5r3 / CVE-2026-44902, Prometheus exporter DoS) - align @opentelemetry/sdk-trace-base, sdk-trace-node, resources to ^2.7.0 to keep all @opentelemetry/* packages on a single core@2.7.1 instance
1 parent d895e0e commit e7e6450

2 files changed

Lines changed: 81 additions & 83 deletions

File tree

apps/sim/package.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -65,11 +65,11 @@
6565
"@modelcontextprotocol/sdk": "1.29.0",
6666
"@monaco-editor/react": "4.7.0",
6767
"@opentelemetry/api": "^1.9.0",
68-
"@opentelemetry/exporter-trace-otlp-http": "^0.200.0",
69-
"@opentelemetry/resources": "^2.0.0",
70-
"@opentelemetry/sdk-node": "^0.200.0",
71-
"@opentelemetry/sdk-trace-base": "2.0.0",
72-
"@opentelemetry/sdk-trace-node": "2.0.0",
68+
"@opentelemetry/exporter-trace-otlp-http": "^0.217.0",
69+
"@opentelemetry/resources": "^2.7.0",
70+
"@opentelemetry/sdk-node": "^0.217.0",
71+
"@opentelemetry/sdk-trace-base": "^2.7.0",
72+
"@opentelemetry/sdk-trace-node": "^2.7.0",
7373
"@opentelemetry/semantic-conventions": "^1.32.0",
7474
"@radix-ui/react-alert-dialog": "^1.1.5",
7575
"@radix-ui/react-avatar": "1.1.10",
@@ -154,7 +154,7 @@
154154
"mysql2": "3.14.3",
155155
"neo4j-driver": "6.0.1",
156156
"next": "16.2.4",
157-
"next-mdx-remote": "^5.0.0",
157+
"next-mdx-remote": "^6.0.0",
158158
"next-runtime-env": "3.3.0",
159159
"next-themes": "^0.4.6",
160160
"nodemailer": "8.0.7",

0 commit comments

Comments
 (0)