Skip to content

Upgrade Next.js to 16.3.8 (critical RCE advisories) - #9

Merged
ralyodio merged 1 commit into
masterfrom
chore/next-16.3.8
Oct 1, 2026
Merged

ralyodio merged 1 commit into
masterfrom
chore/next-16.3.8

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps next 16.1.3 -> 16.3.8 and eslint-config-next 15.5.9 -> 16.3.8 (same version as next) in apps/web.

Advisories fixed:

Breaking change fixed: eslint-config-next 16 ships a native flat config, and loading it through FlatCompat now throws "Converting circular structure to JSON". apps/web/eslint.config.mjs imports eslint-config-next/core-web-vitals directly. It also enables eslint-plugin-react-hooks 7's React Compiler rules; set-state-in-effect and immutability flag 7 spots in existing components, so they are set to warn for now (no component code changed).

Lockfile: narrowed so only next, eslint-config-next (and its new deps: react-hooks 7, typescript-eslint, zod for the hooks plugin), @next/*, sharp/@img and next's nested deps change; a clean bun install --frozen-lockfile passes and a plain bun install leaves it unchanged.

Verified locally: lint, typecheck, tests, build (Next.js 16.3.8). Booted the standalone build under Bun as apps/web/Dockerfile does and compared with live icemap.app: /, /about, /contact, /donate, /favorites, /login, /privacy, /recent, /terms all 200 with identical titles (text length identical except /contact, +/-7 chars of form token); /_next/image (webp) byte-identical to live. No next/og routes.

🤖 Generated with Claude Code

next 16.1.3 -> 16.3.8 and eslint-config-next 15.5.9 -> 16.3.8 in apps/web
for GHSA-vcvr-r3jv-pc5j, GHSA-2xp9-vwfh-vxw4 and GHSA-p293-qw3h-jr36.

eslint-config-next 16 is a native flat config, so eslint.config.mjs
imports it directly instead of going through FlatCompat (which now throws).
The two new React Compiler rules it enables are set to warn.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown
Contributor

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​16.1.3 ⏵ 16.3.861 +15100 +75909970
Updatedeslint-config-next@​15.5.9 ⏵ 16.3.899 +110067 +298100

View full report

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

3 finding(s)

HIGH/CRITICAL: 1 | LOW: 2

Severity Rule Location
HIGH js-ssrf-outbound-request apps/web/src/app/api/media/[...path]/route.ts:28
LOW secret-generic-credential packages/supabase/supabase/config.toml:271
LOW secret-generic-credential packages/supabase/supabase/config.toml:303

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 3ff41eb into master Oct 1, 2026
5 of 6 checks passed
@ralyodio
ralyodio deleted the chore/next-16.3.8 branch October 1, 2026 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant