Lançamento
Next 16.3.5 after a critical set of vulnerabilities, and a weekly security round
The framework behind the platform went from Next 16.2.10 to 16.3.5 after a set of critical vulnerabilities (among them a bypass of the request proxy and remote code execution through image optimisation). After the upgrade the dependency audit reports zero vulnerabilities. From now on every pull request and every week a security round runs: secret scanning over the whole history, a scan of every dependency, an audit of the packages customers run, and a check of the security headers on the site. Findings are weighed and become a report, a patch, or a decision for a person.
Lançado como commit 3f6b1b7