Skip to content

Bump flatted from 3.3.3 to 3.4.2 in /sample-dapps/solana-staking-ui#334

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/sample-dapps/solana-staking-ui/flatted-3.4.2
Open

Bump flatted from 3.3.3 to 3.4.2 in /sample-dapps/solana-staking-ui#334
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/sample-dapps/solana-staking-ui/flatted-3.4.2

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Mar 21, 2026

Bumps flatted from 3.3.3 to 3.4.2.

Commits
  • 3bf0909 3.4.2
  • 885ddcc fix CWE-1321
  • 0bdba70 added flatted-view to the benchmark
  • 2a02dce 3.4.1
  • fba4e8f Merge pull request #89 from WebReflection/python-fix
  • 5fe8648 added "when in Rome" also a test for PHP
  • 53517ad some minor improvement
  • b3e2a0c Fixing recursion issue in Python too
  • c4b46db Add SECURITY.md for security policy and reporting
  • f86d071 Create dependabot.yml for version updates
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Medium Risk
Primarily dependency/lockfile updates, but it includes a major next upgrade (15→16) with a higher Node.js engine requirement and updated transitive deps (e.g., sharp), which may affect build/runtime behavior.

Overview
Updates sample-dapps/solana-staking-ui dependency resolution by bumping flatted to 3.4.2 and refreshing lockfiles.

As part of the lockfile refresh, next is upgraded from 15.1.7 to 16.2.1 (and eslint-config-next to 15.2.3), react/react-dom are bumped to 19.0.1, and image/tooling transitive deps like sharp are updated accordingly.

Written by Cursor Bugbot for commit 5f0581e. This will update automatically on new commits. Configure here.

Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.2.
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 21, 2026
Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

specifier: 15.1.7
version: 15.1.7(react-dom@19.0.0(react@19.0.0))(react@19.0.0)
specifier: ^16.1.1
version: 16.2.1(react-dom@19.0.1(react@19.0.1))(react@19.0.1)
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Major Next.js upgrade hidden in flatted patch bump

High Severity

This PR is titled "Bump flatted from 3.3.3 to 3.4.2" but the lockfile changes include a major version upgrade of next from 15.1.7 to 16.2.1 (specifier changed to ^16.1.1), along with react/react-dom version changes and eslint-config-next updates. Next.js 16 has significant breaking changes including Turbopack as default bundler, Node.js 20.9.0 minimum, middleware API deprecations, and changed caching defaults. These changes far exceed the stated scope and could break the application if merged without proper review and migration steps.

Additional Locations (1)
Fix in Cursor Fix in Web

specifier: ^19.0.0
version: 19.0.0(react@19.0.0)
specifier: 19.0.1
version: 19.0.1(react@19.0.1)
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security fix for flatted not applied in pnpm lockfile

Medium Severity

The PR's stated purpose is to bump flatted from 3.3.3 to 3.4.2 to fix CWE-1321 (prototype pollution). The package-lock.json correctly updates flatted to 3.4.2, but pnpm-lock.yaml still resolves flatted@3.3.3. Instead, the pnpm-lock.yaml received entirely unrelated changes (Next.js, React, sharp upgrades). If the project uses pnpm, the security fix won't be applied.

Fix in Cursor Fix in Web

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants