next dev bound to 0.0.0.0:3000 with the host source dir bind-mounted rw was the entry point malware kept getting dropped through (see prior commit). Now builds and runs `next start`; the bind mount is gone so a compromised container can no longer write onto host disk. Also bumps next to 15.1.11, patching CVE-2025-66478 (critical RCE via the RSC Next-Action header) and the follow-up CVE-2025-67779/55184/ 55183 batch — the installed 15.1.6 was vulnerable to all of them and is the likely actual initial-access vector. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
27 lines
537 B
JSON
27 lines
537 B
JSON
{
|
|
"name": "kkpab-frontend",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"scripts": {
|
|
"dev": "next dev",
|
|
"build": "next build",
|
|
"start": "next start",
|
|
"lint": "next lint"
|
|
},
|
|
"dependencies": {
|
|
"lucide-react": "^0.469.0",
|
|
"next": "15.1.11",
|
|
"react": "19.0.0",
|
|
"react-dom": "19.0.0"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^22.10.2",
|
|
"@types/react": "^19.0.2",
|
|
"@types/react-dom": "^19.0.2",
|
|
"eslint": "^9.17.0",
|
|
"eslint-config-next": "15.1.11",
|
|
"typescript": "^5.7.2"
|
|
}
|
|
}
|
|
|