Skip to content

Bump image-size, @nx/next and less - #5015

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-f4dd8e771c
Open

Bump image-size, @nx/next and less#5015
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-f4dd8e771c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps image-size to 1.2.1 and updates ancestor dependencies image-size, @nx/next and less. These dependencies need to be updated together.

Updates image-size from 1.1.1 to 1.2.1

Release notes

Sourced from image-size's releases.

v1.2.1

Fixes

Full Changelog: image-size/image-size@v1.2.0...v1.2.1

v1.2.0

This release adds support for JPEG-XL ( #409 )

Commits

Updates @nx/next from 19.5.7 to 22.5.4

Release notes

Sourced from @​nx/next's releases.

22.5.4 (2026-03-04)

🚀 Features

  • core: add .nx/polygraph to gitignore in migration and caia (#34659)

🩹 Fixes

  • angular-rspack: use relative path for postcss-cli-resources output (#34681, #34092)
  • core: support canonical SSH URLs when extracting GitHub user/repo slug during nx release (#31684, #31682)
  • core: update sourceRespository description of nx import (#34606)
  • core: update minimatch to 10.2.4 (#34660)
  • core: skip writing deps cache if already up-to-date (#34582)
  • core: resolve false positive loop detection when running with Bun (#34640, #0, #1, #2, #3, #4, #5, #6, #33997)
  • core: fall back to invoking PM in detection (#34691)
  • core: restore CNW user flow to match v22.1.3 (#34671)
  • gradle: tee batch runner output to stderr for terminal display (#34630)
  • maven: synchronize batch runner invoke() to prevent concurrent access (#34600)
  • misc: boost CLI command reference search ranking (#34625)
  • misc: fix broken nx.dev redirects and remove legacy redirect-rules files (#34673)
  • misc: use pathToFileURL for cross-platform path handling in postcss-cli-resources (#34676, #33052)
  • misc: exclude .netlify paths from Framer proxy edge function (1ce5e91f5e)
  • repo: reset package.json files after local release (#34648)
  • repo: remove redundant inputs override for build-base target (#34649)
  • vitest: respect reporters from target options in vitest executor (#34663, #34495)

❤️ Thank You

22.5.3 (2026-02-26)

🚀 Features

  • core: add --json flag for better AX to nx list (#34551)
  • core: add passthrough for nx-cloud apply-locally command (#34557)
  • core: add explicit cloud opt-out to CNW (#34580)

🩹 Fixes

... (truncated)

Commits
  • 24ddad0 fix(nextjs): reset daemon client after project graph creation in withNx (#34518)
  • e3eedf9 docs(misc): update the docs to use more direct language (#34264)
  • 3fcd200 fix(react): remove file-loader dependency and update svgr migration (#34218)
  • 42b1f14 fix(misc): deprecate setup-tailwind generators (#34097)
  • 574d841 chore(core): update to latest version of tsquery (#34067)
  • a13f5eb chore(repo): update nx to 22.4.0-beta.1 (#33968)
  • 9fb5a6c fix(linter): handle variable references in replaceOverride (#34026)
  • 6f85b83 cleanup(repo): format all files (#33902)
  • 45cdece fix(nextjs): accept fileName option to generate page (#30013)
  • f025232 fix(misc): update output location of ai-migration files (#33696)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​nx/next since your current version.


Updates less from 4.1.3 to 4.8.0

Release notes

Sourced from less's releases.

Release v4.8.0

Changes

See CHANGELOG.md for details.

Installation

npm install less@4.8.0

Release v4.7.0

Changes

See CHANGELOG.md for details.

Installation

npm install less@4.7.0

Release v4.6.7

Changes

See CHANGELOG.md for details.

Installation

npm install less@4.6.7

Release v4.6.6

Changes

See CHANGELOG.md for details.

Installation

npm install less@4.6.6

Release v4.6.5

Changes

See CHANGELOG.md for details.

Installation

... (truncated)

Changelog

Sourced from less's changelog.

v4.8.0 (2026-07-22)

Changes

  • #4473 fix(mixing): resolves issue #4234 (@​puckowski)
  • #4472 Fix boolean() parsing for comparisons between inline condition expressions (@​app/copilot-swe-agent)

Deprecation Warnings

  • #4475 Deprecate numeric-leading and dash-only variable names, dash-only mixin names, and dynamic @charset interpolation for removal in Less 5.x. Less 4 preserves the existing output while warning; migrate names to valid identifiers and use a static quoted @charset declaration. (@​matthew-dean)

v4.7.0 (2026-07-18)

Changes

v4.6.7 (2026-06-20)

Changes

  • #4457 Fix failing "Request Copilot review" CI job (@​app/copilot-swe-agent)
  • #4451 chore: release v4.6.6 (@​app/github-actions)

v4.6.6 (2026-06-14)

Changes

v4.6.5 (2026-06-13)

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for less since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [image-size](https://github.com/image-size/image-size) to 1.2.1 and updates ancestor dependencies [image-size](https://github.com/image-size/image-size), [@nx/next](https://github.com/nrwl/nx/tree/HEAD/packages/next) and [less](https://github.com/less/less.js). These dependencies need to be updated together.


Updates `image-size` from 1.1.1 to 1.2.1
- [Release notes](https://github.com/image-size/image-size/releases)
- [Commits](image-size/image-size@v1.1.1...v1.2.1)

Updates `@nx/next` from 19.5.7 to 22.5.4
- [Release notes](https://github.com/nrwl/nx/releases)
- [Commits](https://github.com/nrwl/nx/commits/22.5.4/packages/next)

Updates `less` from 4.1.3 to 4.8.0
- [Release notes](https://github.com/less/less.js/releases)
- [Changelog](https://github.com/less/less.js/blob/master/CHANGELOG.md)
- [Commits](less/less.js@v4.1.3...v4.8.0)

---
updated-dependencies:
- dependency-name: image-size
  dependency-version: 1.2.1
  dependency-type: indirect
- dependency-name: "@nx/next"
  dependency-version: 22.5.4
  dependency-type: direct:production
- dependency-name: less
  dependency-version: 4.8.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 27, 2026
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 duplication

Metric Results
Duplication 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR is currently incomplete and introduces significant stability risks. While the title and description specify updates for multiple packages, the implementation fails to include the changes for image-size and less. This is particularly critical as the image-size update is intended to resolve a known Denial of Service (DoS) security vulnerability. Furthermore, the update of @nx/next across several major versions without aligning sibling workspace dependencies or including migration scripts is highly likely to cause build failures and workspace instability. These gaps must be addressed to fulfill the PR requirements and ensure system reliability.

About this PR

  • The implementation is incomplete. The updates for image-size and less are entirely missing from the manifest changes, leaving the stated security objectives of this PR unfulfilled.
  • A major version mismatch has been introduced within the Nx ecosystem. Updating @nx/next while sibling packages remain on an older major version is highly likely to cause build or runtime errors. It is recommended to align all workspace dependencies and run necessary migration generators to handle breaking changes.

Test suggestions

  • Verify workspace compatibility when @nx/next is on a newer major version while sibling dependencies remain on older versions
  • Validate the image-size update fixes the security vulnerability (DoS) without regressing image dimension parsing
  • Confirm the less update compiles existing stylesheets correctly and check for deprecation warnings
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify workspace compatibility when @nx/next is on a newer major version while sibling dependencies remain on older versions
2. Validate the image-size update fixes the security vulnerability (DoS) without regressing image dimension parsing
3. Confirm the less update compiles existing stylesheets correctly and check for deprecation warnings

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread package.json
"@nx/linter": "^19.4.2",
"@nx/nest": "^19.0.4",
"@nx/next": "^19.5.2",
"@nx/next": "^22.5.4",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

The implementation is missing the update for image-size required to address a Denial of Service (DoS) security vulnerability. Additionally, the update for less mentioned in the requirements is not reflected in this file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants