# Dependency compatibility and audit

Next.js and React are pinned to the latest stable versions available during this migration; the lockfile fixes transitive versions too. ESLint is pinned to **9.39.5**, the latest compatible 9.x release: Next.js 16.3.8’s React/import/accessibility plugins still declare ESLint 9 peer ranges, and ESLint 10.12.0 failed with `scopeManager.addGlobals is not a function`. ESLint 9 is now out of upstream support; update it when Next.js’s bundled lint plugins support ESLint 10.

The production audit reports **zero vulnerabilities**. The full audit currently reports **five high-severity entries** stemming from one unpatched development-only `braces` advisory through Next.js’s ESLint plugin (`fast-glob → micromatch → braces`). The [upstream advisory](https://github.com/advisories/GHSA-vfj7-8cjw-p6xm) lists no patched release. These packages are lint tooling, not production dependencies. Do not use `npm audit fix --force`, which proposes downgrading the Next.js ESLint configuration to version 14.2.35.