Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
{

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "ajv" 6.12.6 is vulnerable to CVE-2025-69873 - ajv has ReDoS when using `$data` option.

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "brace-expansion" 1.1.12 is vulnerable to CVE-2026-33750 - brace-expansion: Zero-step sequence causes process hang and memory exhaustion. Vulnerability score: 6.5 (medium).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "brace-expansion" 2.0.2 is vulnerable to CVE-2026-33750 - brace-expansion: Zero-step sequence causes process hang and memory exhaustion. Vulnerability score: 6.5 (medium).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "flatted" 3.3.3 is vulnerable to CVE-2026-32141 - flatted vulnerable to unbounded recursion DoS in parse() revive phase. Vulnerability score: 7.5 (high).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "flatted" 3.3.3 is vulnerable to CVE-2026-33228 - Prototype Pollution via parse() in NodeJS flatted.

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "minimatch" 3.1.2 is vulnerable to CVE-2026-27904 - minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions. Vulnerability score: 7.5 (high).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "minimatch" 3.1.2 is vulnerable to CVE-2026-26996 - minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern.

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "minimatch" 3.1.2 is vulnerable to CVE-2026-27903 - minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments. Vulnerability score: 7.5 (high).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "minimatch" 9.0.5 is vulnerable to CVE-2026-27904 - minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions. Vulnerability score: 7.5 (high).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "minimatch" 9.0.5 is vulnerable to CVE-2026-26996 - minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern.

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "minimatch" 9.0.5 is vulnerable to CVE-2026-27903 - minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments. Vulnerability score: 7.5 (high).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "picomatch" 2.3.1 is vulnerable to CVE-2026-33672 - Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching. Vulnerability score: 5.3 (medium).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "picomatch" 2.3.1 is vulnerable to CVE-2026-33671 - Picomatch has a ReDoS vulnerability via extglob quantifiers. Vulnerability score: 7.5 (high).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "picomatch" 4.0.3 is vulnerable to CVE-2026-33672 - Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching. Vulnerability score: 5.3 (medium).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "picomatch" 4.0.3 is vulnerable to CVE-2026-33671 - Picomatch has a ReDoS vulnerability via extglob quantifiers. Vulnerability score: 7.5 (high).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "postcss" 8.4.31 is vulnerable to CVE-2026-41305 - PostCSS has XSS via Unescaped </style> in its CSS Stringify Output. Vulnerability score: 6.1 (medium).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "postcss" 8.5.6 is vulnerable to CVE-2026-41305 - PostCSS has XSS via Unescaped </style> in its CSS Stringify Output. Vulnerability score: 6.1 (medium).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "undici" 7.18.2 is vulnerable to CVE-2026-1525 - Undici has an HTTP Request/Response Smuggling issue. Vulnerability score: 6.5 (medium).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "undici" 7.18.2 is vulnerable to CVE-2026-1527 - Undici has CRLF Injection in undici via `upgrade` option. Vulnerability score: 4.6 (medium).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "undici" 7.18.2 is vulnerable to CVE-2026-1528 - Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client. Vulnerability score: 7.5 (high).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "undici" 7.18.2 is vulnerable to CVE-2026-2581 - Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS. Vulnerability score: 5.9 (medium).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "undici" 7.18.2 is vulnerable to CVE-2026-2229 - Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation. Vulnerability score: 7.5 (high).

Check failure on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "undici" 7.18.2 is vulnerable to CVE-2026-1526 - Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression. Vulnerability score: 7.5 (high).

Check warning on line 1 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "ws" 8.18.0 is vulnerable to CVE-2026-45736 - ws: Uninitialized memory disclosure. Vulnerability score: 4.4 (medium).
"name": "games",
"version": "0.1.0",
"private": true,
Expand All @@ -9,13 +9,14 @@
"lint": "next lint"
},
"dependencies": {
"next": "^15.5.9",

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44575 - Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes. Vulnerability score: 7.5 (high).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-45109 - Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up. Vulnerability score: 7.5 (high).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44573 - Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n. Vulnerability score: 7.5 (high).

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44572 - Next.js's Middleware / Proxy redirects can be cache-poisoned. Vulnerability score: 3.7 (low).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-27980 - Next.js: Unbounded next/image disk cache growth can exhaust storage.

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44574 - Next.js has a Middleware / Proxy bypass through dynamic route parameter injection. Vulnerability score: 8.1 (high).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to GHSA-8h8q-6873-q5fj - Next.js Vulnerable to Denial of Service with Server Components. Vulnerability score: 7.5 (high).

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2025-59471 - Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration. Vulnerability score: 5.9 (medium).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44578 - Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades. Vulnerability score: 8.6 (high).

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44581 - Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces. Vulnerability score: 4.7 (medium).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-29057 - Next.js: HTTP request smuggling in rewrites.

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44580 - Next.js has cross-site scripting in beforeInteractive scripts with untrusted input. Vulnerability score: 6.1 (medium).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to GHSA-h25m-26qc-wcjf - Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components. Vulnerability score: 7.5 (high).

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44577 - Next.js has a Denial of Service in the Image Optimization API. Vulnerability score: 5.9 (medium).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44579 - Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components. Vulnerability score: 7.5 (high).

Check failure on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Error

Artifact "next" 15.5.9 is vulnerable to GHSA-q4gf-8mx6-v5v3 - Next.js has a Denial of Service with Server Components. Vulnerability score: 7.5 (high).

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44582 - Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting. Vulnerability score: 3.7 (low).

Check warning on line 12 in package.json

View check run for this annotation

Codeac.io / Codeac Code Quality

NPM Vulnerability Warning

Artifact "next" 15.5.9 is vulnerable to CVE-2026-44576 - Next.js vulnerable to cache poisoning in React Server Component responses. Vulnerability score: 5.4 (medium).
"react": "^19.0.0",
"react-dom": "^19.0.0"
},
"devDependencies": {
"@eslint/eslintrc": "^3",
"@tailwindcss/postcss": "^4",
"@types/node": "^20.17.6",
"eslint": "^9",
"eslint-config-next": "15.3.4",
"tailwindcss": "^4",
Expand Down
Loading