Author SHA1 Message Date
Sharang ParnerkarandClaude Fable 5 1886936463 fix(deps): next-auth beta.30 -> beta.32 — the advisory targets next-auth itself
ci / e2e (pull_request) Blocked by required conditions
ci / shared (pull_request) Failing after 14s
ci / test (pull_request) Successful in 10m18s
ci / image (pull_request) Skipped
The #22 bump patched @auth/core to 0.41.3 but trivy also flags the
next-auth package directly (CVE-2026-73420 CRITICAL + CVE-2026-73421,
existence-based auth bypass on configuration errors), both fixed in
5.0.0-beta.32. Tests 80/80 at 100% coverage; typecheck, lint, build
clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-31 10:40:09 +02:00

Diff Content Not Available