Dev Stack Release Audit: Next.js 16.3.6 RCE Fix, SvelteKit 3.0 and GitHub CLI 2.102 Security Patches

Executive Summary
- Security (critical): Next.js 16.3.6 and 15.5.26 fix a remote code execution issue in the Node.js ImageResponse implementation (next/og). Affected: >=16.2.0 <16.3.6.
- Major release: SvelteKit 3.0.0 lands with Node 22.17+, TypeScript 6+, Vite 8 and the $lib to #lib change.
- Security: GitHub CLI 2.102.0 patches four vulnerabilities, including symlink write issues and attestation verification bypasses.
- Platform: npm trusted publishing gains opt-in dist-tag permissions, and GitHub adds rate limits and structured forms for private vulnerability reports.
Scope note: this audit covers what could be verified from official sources today. No verified notable releases surfaced for the rest of the tracked stack in this run, so they are omitted rather than guessed.
Next.js: Critical RCE in ImageResponse
The Next.js security update describes improper escaping in SVG output generated by Satori that, combined with flaws in other upstream dependencies, could lead to remote code execution in the Node.js ImageResponse implementation. See advisory GHSA-vcvr-r3jv-pc5j and the upstream Satori advisory. The Edge ImageResponse implementation is not affected. Next.js 15.x is not affected by the RCE; 15.5.26 only adds hardening.
npm install [email protected] # for 16.3
npm install [email protected] # for 15.5 (hardening only)SvelteKit 3.0: Breaking Changes to Plan For
The SvelteKit 3.0.0 release (October 1) requires Node 22.17+, TypeScript 6+, Vite 8.0.12+ and Svelte 5.56.4+. Notable changes: the $app/stores module is removed in favor of $app/state, $lib becomes the standard subpath import #lib, cookies move to v2 (ASCII-only names), fail() status codes are now used in form action responses, and all load functions refresh when navigating to the current URL. Release trackers such as Releasebot also list the config moving toward vite.config.ts.
// before
import { page } from '$app/stores';
import { helper } from '$lib/helper.js';
// after (SvelteKit 3)
import { page } from '$app/state';
import { helper } from '#lib/helper.js'; // explicit extension requiredGitHub CLI 2.102.0: Four Security Fixes
The v2.102.0 release (September 30) fixes: symlink-following writes in download commands (GHSA-39wj-f2f4-978v), case-insensitive --source-ref matching in gh attestation verify (GHSA-4mq3-hpgx-9cx8), option injection in gh skill search (GHSA-qcwj-mr2r-2cx7), and prefix-only --signer-workflow matching (GHSA-wjmr-j3rp-mh2g). If you rely on attestation verification in CI, update now.
GitHub Platform and npm Supply Chain
Per the GitHub release feed: npm trusted publishing now has opt-in, disabled-by-default dist-tag permissions for OIDC workflows (September 30); private vulnerability reports get daily per-user rate limits and a structured form customizable via .github/VULNERABILITY_REPORT.yml (October 1); macOS 14 runners retire November 2 with brownouts October 5-31; and Actions Runner Controller 0.15.0 shipped.
Action Items
- Upgrade Next.js 16.2.x-16.3.5 to 16.3.6 immediately if you use next/og on Node.js.
- Update gh to 2.102.0 on developer machines and CI images.
- Audit SvelteKit projects for $app/stores and $lib usage before migrating to 3.0.
- Move off macos-14 runners before the November 2 retirement.
Comments
Share your thoughts and join the conversation
Leave a Comment
Keep reading.

Daily SEO Note — October 3, 2026: Google Defines What Counts as Main Content

Dev Stack Release Audit: Next.js 16.3.8 SSRF Fix, Keycloak 26.7.4 and PostgreSQL Security Patches

