Skip to content

fix(deps): bump Next.js 16.1.6 → 16.2.10 to clear high security advisories - #19

Merged
iaj6 merged 1 commit into
mainfrom
fix/nextjs-advisories
Jul 12, 2026
Merged

iaj6 merged 1 commit into
mainfrom
fix/nextjs-advisories

Conversation

@iaj6

@iaj6 iaj6 commented Jul 12, 2026

Copy link
Copy Markdown
Owner

npm audit flagged next@16.1.6 with 2 high + several moderate advisories,
including middleware/proxy bypass variants (GHSA-267c-6grr-h53f,
GHSA-26hh-7cqf-hhc6, GHSA-492v-c6pp-mqqv), RSC cache poisoning
(GHSA-wfc6-r584-vfw7, GHSA-vfv6-92ff-j949), and a batch of DoS issues.
16.2.10 (current stable) clears every direct Next.js advisory.

eslint-config-next bumped in lockstep. Lockfile regenerated with
--include=optional so the Linux-native optionals (@rollup/rollup-linux-,
@emnapi/
, swc binaries) stay present for CI's npm ci on Linux; verified
locally with a clean-room npm ci + full build + test run.

Known remaining (not addressed here):

  • drizzle-orm < 0.45.2 high (GHSA-gpj5-g38j-94v9) — separate bump.
  • moderate XSS in Next's bundled postcss copy — fixed upstream only in
    the 16.3 canary line; not worth overriding a framework-pinned internal.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

…sories

npm audit flagged next@16.1.6 with 2 high + several moderate advisories,
including middleware/proxy bypass variants (GHSA-267c-6grr-h53f,
GHSA-26hh-7cqf-hhc6, GHSA-492v-c6pp-mqqv), RSC cache poisoning
(GHSA-wfc6-r584-vfw7, GHSA-vfv6-92ff-j949), and a batch of DoS issues.
16.2.10 (current stable) clears every direct Next.js advisory.

eslint-config-next bumped in lockstep. Lockfile regenerated with
--include=optional so the Linux-native optionals (@rollup/rollup-linux-*,
@emnapi/*, swc binaries) stay present for CI's npm ci on Linux; verified
locally with a clean-room npm ci + full build + test run.

Known remaining (not addressed here):
- drizzle-orm < 0.45.2 high (GHSA-gpj5-g38j-94v9) — separate bump.
- moderate XSS in Next's bundled postcss copy — fixed upstream only in
  the 16.3 canary line; not worth overriding a framework-pinned internal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@iaj6
iaj6 merged commit 5308c16 into main Jul 12, 2026
3 checks passed
@iaj6
iaj6 deleted the fix/nextjs-advisories branch July 12, 2026 03:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant