Skip to content

build(deps): bump next from 16.2.4 to 16.2.6 in /frontend in the npm_and_yarn group across 1 directory - #167

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/frontend/npm_and_yarn-152f59e559
Closed

build(deps): bump next from 16.2.4 to 16.2.6 in /frontend in the npm_and_yarn group across 1 directory#167
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/frontend/npm_and_yarn-152f59e559

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /frontend directory: next.

Updates next from 16.2.4 to 16.2.6

Release notes

Sourced from next's releases.

v16.2.6

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.

Security Fixes

The following advisories have been addressed:

High:

Moderate:

Low:

Core Changes

  • fix: preserve HTTP access fallbacks during prerender recovery (#92231)
  • Fix fallback route params case in app-page handler (#91737)
  • Fix invalid HTML response for route-level RSC requests in deployment adapter (#91541)
  • Patch setHeader for direct route handlers (#93101)
  • Include deployment id in cacheHandlers keys (#93453)
  • Fix double-encoding of URL pathname parts in client param parsing (#93491)

v16.2.5

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.

Security Fixes

The following advisories have been addressed:

High:

... (truncated)

Commits
  • ee6e79b v16.2.6
  • afa053d Turbopack: Match proxy matchers with webpack implementation (#93594)
  • 97a154e Turbopack: Fix middleware matcher suffix (#93590)
  • 83899bc [backport] Disable build caches for production/staging/force-preview deploys ...
  • 7b222b9 [backport][test] Pin package manager to patch versions (#93595)
  • a8dc24f [backport] Turbopack: more strict vergen setup (#93587)
  • 766148f v16.2.5
  • 0dd9483 fix: add explicit checks for RSC header (#83) (#98)
  • d166096 fix proxy matching for segment prefetch URLs (#89) (#96)
  • 9d50c0b Strip next-resume header from incoming requests (#92)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.


Summary by CodeRabbit

  • Chores
    • Updated Next.js to version 16.2.6, including latest bug fixes and stability improvements.

Review Change Stack

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 12, 2026
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 3 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

2 similar comments
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 3 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 3 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

@coderabbitai

coderabbitai Bot commented May 12, 2026

Copy link
Copy Markdown
Contributor

Note

.coderabbit.yaml has unrecognized properties

CodeRabbit is using all valid settings from your configuration. Unrecognized properties (listed below) have been ignored and may indicate typos or deprecated fields that can be removed.

⚠️ Parsing warnings (1)
Validation error: Unrecognized key(s) in object: 'version'
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json
📝 Walkthrough

Walkthrough

The frontend/package.json file is updated to bump Next.js from version 16.2.4 to 16.2.6.

Changes

Dependency Update

Layer / File(s) Summary
Next.js version bump
frontend/package.json
Next.js dependency is updated from 16.2.4 to 16.2.6 in the frontend package configuration.

🎯 1 (Trivial) | ⏱️ ~2 minutes

🐰 A hop, a skip, a version bound,
Next.js patch updates are found!
Sixteen-two-six sits snug and tight,
Package.json now gleams just right,
A tiny bump, and all is sound.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: upgrading Next.js from version 16.2.4 to 16.2.6 in the frontend directory.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/npm_and_yarn/frontend/npm_and_yarn-152f59e559

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 3 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 3 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 2 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 2 required check(s) are not successful on 37c9913.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
frontend/package.json (1)

36-36: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update eslint-config-next to match the next package version.

eslint-config-next is at 16.2.4 while next is at 16.2.6. Update to 16.2.6 to ensure ESLint rules align with the framework version and its features.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@frontend/package.json` at line 36, Update the dev dependency
"eslint-config-next" to match the "next" package version (change
"eslint-config-next" from 16.2.4 to 16.2.6 in package.json) so ESLint rules
align with Next.js; after updating the version string for "eslint-config-next"
run your package manager (npm/yarn/pnpm install) to refresh lockfile and
node_modules.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@frontend/package.json`:
- Line 36: Update the dev dependency "eslint-config-next" to match the "next"
package version (change "eslint-config-next" from 16.2.4 to 16.2.6 in
package.json) so ESLint rules align with Next.js; after updating the version
string for "eslint-config-next" run your package manager (npm/yarn/pnpm install)
to refresh lockfile and node_modules.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: a2c429fd-727c-40c0-ad60-a63b25875df6

📥 Commits

Reviewing files that changed from the base of the PR and between 10d108b and 37c9913.

⛔ Files ignored due to path filters (1)
  • frontend/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • frontend/package.json

@greptile-apps

greptile-apps Bot commented May 12, 2026

Copy link
Copy Markdown

Greptile Summary

  • next16.2.4에서 16.2.6으로 업그레이드하는 보안 패치 PR입니다. 미들웨어/프록시 우회(GHSA-267c-6grr-h53f, GHSA-492v-c6pp-mqqv 등 다수), Server Components DoS(GHSA-8h8q-6873-q5fj), SSRF(GHSA-c4j6-fc7j-m34r), XSS(GHSA-ffhc-5mcf-pf4q, GHSA-gx5p-jg67-6x7h) 등 다수의 High/Moderate 심각도 취약점을 포함한 보안 수정이 포함되어 있습니다.
  • package.json의 버전 지정과 package-lock.json@next/env, @next/swc-* 등 관련 하위 패키지가 모두 일관되게 16.2.6으로 업데이트되었습니다.
  • 이전 리뷰 스레드에서 지적된 fsevents dev 플래그 제거 및 @tailwindcss/oxide-wasm32-wasi 하위 패키지 추가 변경 사항은 여전히 포함되어 있으며, 이는 next 업그레이드와 무관한 변경입니다.

Confidence Score: 5/5

다수의 보안 취약점을 수정하는 패치 버전 업그레이드로, 안전하게 머지 가능합니다.

순수한 보안 패치(16.2.4 → 16.2.6)로 API 변경 없이 취약점만 수정합니다. 이전 스레드에서 지적된 무관한 lockfile 변경(fsevents, tailwindcss)은 프로덕션에 영향이 없는 dev/optional 패키지입니다.

특별히 주의가 필요한 파일은 없습니다.

Important Files Changed

Filename Overview
frontend/package.json next 버전을 16.2.4에서 16.2.6으로 단순 업데이트 — 단일 라인 변경으로 문제 없음
frontend/package-lock.json next 및 관련 @next/* 패키지 lockfile 갱신 완료. 이전 스레드에서 지적된 fsevents dev 플래그 제거 및 @tailwindcss/oxide-wasm32-wasi 하위 패키지 추가는 여전히 포함되어 있음

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[dependabot PR] --> B[package.json\nnext 16.2.4 → 16.2.6]
    B --> C[package-lock.json 갱신]
    C --> D["@next/env 16.2.6"]
    C --> E["@next/swc-* 16.2.6\n(darwin-arm64, darwin-x64,\nlinux-arm64-gnu/musl,\nlinux-x64-gnu/musl 등)"]
    C --> F[기타 lockfile 변경\nfsevents dev 플래그 제거\n@tailwindcss/oxide 하위 패키지 추가]
    B --> G{보안 수정 포함}
    G --> H["High: 미들웨어·프록시 우회 (×5)\nDoS (×2), SSRF (×1)"]
    G --> I["Moderate: XSS (×2)\nCache poisoning (×1)\nImage Optimization DoS (×1)"]
    G --> J["Low: Cache poisoning (×2)"]
Loading

Reviews (2): Last reviewed commit: "build(deps): bump next" | Re-trigger Greptile

Comment thread frontend/package-lock.json
Comment thread frontend/package-lock.json
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 37c9913984cf409949f28f7d0ab627defa123400:

  • 2 unresolved current review thread(s) remain.\n- Missing current-head CodeRabbit/coderabbitai evidence for 37c9913.\n

Bumps the npm_and_yarn group with 1 update in the /frontend directory: [next](https://github.com/vercel/next.js).


Updates `next` from 16.2.4 to 16.2.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](vercel/next.js@v16.2.4...v16.2.6)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.2.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump next from 16.2.4 to 16.2.6 in /frontend in the npm_and_yarn group across 1 directory build(deps): bump next from 16.2.4 to 16.2.6 in /frontend in the npm_and_yarn group across 1 directory May 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/npm_and_yarn-152f59e559 branch from 37c9913 to 6a840de Compare May 12, 2026 14:27
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 6a840de6cf1acae346985d68b739630f426985ee:

  • 1 unresolved current review thread(s) remain.\n- 2 required check(s) are not successful on 6a840de.\n- Missing current-head CodeRabbit/coderabbitai evidence for 6a840de.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 6a840de6cf1acae346985d68b739630f426985ee:

  • 2 required check(s) are not successful on 6a840de.\n- Missing current-head CodeRabbit/coderabbitai evidence for 6a840de.\n

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 6a840de6cf1acae346985d68b739630f426985ee:

  • 2 required check(s) are not successful on 6a840de.\n- Missing current-head CodeRabbit/coderabbitai evidence for 6a840de.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 6a840de6cf1acae346985d68b739630f426985ee:

  • 1 required check(s) are not successful on 6a840de.\n- Missing current-head CodeRabbit/coderabbitai evidence for 6a840de.\n

@dependabot @github

dependabot Bot commented on behalf of github May 13, 2026

Copy link
Copy Markdown
Contributor Author

Looks like next is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this May 13, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/npm_and_yarn-152f59e559 branch May 13, 2026 04:39
@seonghobae

Copy link
Copy Markdown
Contributor

이 PR은 (보안 잔여 경보 정리)에서 포함·병합되었습니다. 최신 릴리스 기준은 v0.13.0 입니다.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant