chore(deps): dev dependency security fixes (#24275)
## Summary Batched **dev** dependency security fixes. One commit per vulnerability. ### Fixes - `next` 15.5.21 → 15.5.24 — GHSA-p293-qw3h-jr36 (CVE-2026-75604) (critical) — https://github.com/getsentry/sentry-javascript/security/dependabot/2526 - `next` 15.5.21 → 15.5.24 — GHSA-2xp9-vwfh-vxw4 (critical) — https://github.com/getsentry/sentry-javascript/security/dependabot/2527 - `astro` 7.2.4 → 7.2.8 — GHSA-26w7-cxv4-gfx2 (critical) — https://github.com/getsentry/sentry-javascript/security/dependabot/2524 Both `next` advisories are patched by the same release (15.5.24), so they share one commit. The `next` bump covers the `packages/nextjs` dev dependency (plus the root `yarn.lock`) and the four Next 15 e2e test apps. For `nextjs-15-basepath` and `nextjs-15-t3` the existing carets (`^15`, `^15.5.13`) already resolved to a patched version at install time, but the range floors were raised to `^15.5.24` so the manifests themselves are no longer in the advisory range. `packages/nextjs`'s `next` **peerDependency** range (`^14.0 || ^15.0.0-rc.0 || ^16.0.0-0`) is deliberately left untouched — `yarn-update-dependency` rewrites it to a single pinned range, which would silently drop Next 14 and 16 support for SDK users. Only the dev dependency was bumped. No `resolutions` entries were added. ### Skipped — needs human - `astro` in `packages/astro` (dev dependency `^4.16.19`) — 7.2.8 is the only patched release, so fixing requires a major bump 4 → 7 — https://github.com/getsentry/sentry-javascript/security/dependabot/2524 - `astro` in the `astro-4`, `astro-5`, `astro-5-cf-workers`, `astro-6` and `astro-6-cf-workers` e2e apps — each app exists to test that specific major; the only patched release is 7.2.8, so the fix would mean bumping away from the major under test — https://github.com/getsentry/sentry-javascript/security/dependabot/2524 - `next` in the `nextjs-14`, `nextjs-app-dir`, `nextjs-pages-dir`, `supabase-nextjs` and `nextjs-orpc` e2e apps (pinned `14.2.35`) — the patched release is 15.5.24, so a major bump 14 → 15 would be needed and these apps exist to test Next 14 — https://github.com/getsentry/sentry-javascript/security/dependabot/2526, https://github.com/getsentry/sentry-javascript/security/dependabot/2527 These are all dev/CI-only manifests, so the remaining exposure is confined to CI and never reaches shipped SDK code. They likely want a dismissal (`tolerable_risk`) rather than a bump, but that call is left to a human. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
J
javascript-sdk-gitflow[bot] committed
4ff3673adf0791e84037f45bcb6ae56cd22781b5
Parent: b470aca
Committed by GitHub <noreply@github.com>
on 10/2/2026, 7:53:23 AM