SIGN IN SIGN UP

chore(deps): dev dependency security fixes (#24275)

## Summary

Batched **dev** dependency security fixes. One commit per vulnerability.

### Fixes

- `next` 15.5.21 → 15.5.24 — GHSA-p293-qw3h-jr36 (CVE-2026-75604)
(critical) —
https://github.com/getsentry/sentry-javascript/security/dependabot/2526
- `next` 15.5.21 → 15.5.24 — GHSA-2xp9-vwfh-vxw4 (critical) —
https://github.com/getsentry/sentry-javascript/security/dependabot/2527
- `astro` 7.2.4 → 7.2.8 — GHSA-26w7-cxv4-gfx2 (critical) —
https://github.com/getsentry/sentry-javascript/security/dependabot/2524

Both `next` advisories are patched by the same release (15.5.24), so
they share one commit.

The `next` bump covers the `packages/nextjs` dev dependency (plus the
root `yarn.lock`) and the four Next 15 e2e test apps. For
`nextjs-15-basepath` and `nextjs-15-t3` the existing carets (`^15`,
`^15.5.13`) already resolved to a patched version at install time, but
the range floors were raised to `^15.5.24` so the manifests themselves
are no longer in the advisory range.

`packages/nextjs`'s `next` **peerDependency** range (`^14.0 ||
^15.0.0-rc.0 || ^16.0.0-0`) is deliberately left untouched —
`yarn-update-dependency` rewrites it to a single pinned range, which
would silently drop Next 14 and 16 support for SDK users. Only the dev
dependency was bumped.

No `resolutions` entries were added.

### Skipped — needs human

- `astro` in `packages/astro` (dev dependency `^4.16.19`) — 7.2.8 is the
only patched release, so fixing requires a major bump 4 → 7 —
https://github.com/getsentry/sentry-javascript/security/dependabot/2524
- `astro` in the `astro-4`, `astro-5`, `astro-5-cf-workers`, `astro-6`
and `astro-6-cf-workers` e2e apps — each app exists to test that
specific major; the only patched release is 7.2.8, so the fix would mean
bumping away from the major under test —
https://github.com/getsentry/sentry-javascript/security/dependabot/2524
- `next` in the `nextjs-14`, `nextjs-app-dir`, `nextjs-pages-dir`,
`supabase-nextjs` and `nextjs-orpc` e2e apps (pinned `14.2.35`) — the
patched release is 15.5.24, so a major bump 14 → 15 would be needed and
these apps exist to test Next 14 —
https://github.com/getsentry/sentry-javascript/security/dependabot/2526,
https://github.com/getsentry/sentry-javascript/security/dependabot/2527

These are all dev/CI-only manifests, so the remaining exposure is
confined to CI and never reaches shipped SDK code. They likely want a
dismissal (`tolerable_risk`) rather than a bump, but that call is left
to a human.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
J
javascript-sdk-gitflow[bot] committed
4ff3673adf0791e84037f45bcb6ae56cd22781b5
Parent: b470aca
Committed by GitHub <noreply@github.com> on 10/2/2026, 7:53:23 AM