Skip to content

Update nextjs monorepo to v16.2.10 - #4038

Merged
amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/nextjs-monorepo
Jul 8, 2026
Merged

amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/nextjs-monorepo

Conversation

@amitsingh-007

@amitsingh-007 amitsingh-007 commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@next/eslint-plugin-next (source) 16.1.6 → 16.2.10 age confidence
next (source) 16.1.6 → 16.2.10 age confidence

Release Notes

vercel/next.js (@​next/eslint-plugin-next)

v16.2.10

Compare Source

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 16.2.4.

v16.2.9

Compare Source

Empty release to ensure next@latest points at a stable release. Next.js only allows publishing with Trusted Publishing enabled. In order to fix NPM dist-tags, we have to release a new version. Updating dist-tags is not possible with Trusted Publishing.

v16.2.8

Compare Source

Release with no changes in an attempt to fix next@latest pointing at a prerelease version.

v16.2.7

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • Backport documentation fixes for v16.2 (#​93804)
  • [backport] Patch playwright-core to resolve _finishedPromise on requestFailed (#​93920)
  • [backport] Fix dev mode hydration failure when page is served from HTTP cache (#​93492)
  • [backport] Fix catch-all router.query corruption with basePath + rewrites (#​93917)
  • [backport] Encode non-ASCII characters in cache tags at construction (#​93918)
  • [backport] Fix server action forwarding loop with middleware rewrites (#​93919)
  • [backport] Turbopack: switch from base40 to base38 hash encoding (#​93932)
  • [ci] Disable hanging node 24 typescript tests on 16.2 backport branch (#​94164)
  • [backport] Fix "type: module" in project dir when using standalone or adapters (#​94050)
  • [backport] Propagate adapter preferred regions (#​94200)
  • [16.2.x] Don't drop FormData entries (#​94240)
  • [backport] feat(turbopack): add LocalPathOrProjectPath PostCSS config resolution (#​94284)
Credits

Huge thanks to @​eps1lon, @​icyJoseph, @​unstubbable, @​mischnic, @​bgw, @​timneutkens, and @​lukesandberg for helping!

v16.2.6

Compare Source

[!NOTE]
This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.

Security Fixes

The following advisories have been addressed:

High:

Moderate:

Low:

Core Changes
  • fix: preserve HTTP access fallbacks during prerender recovery (#​92231)
  • Fix fallback route params case in app-page handler (#​91737)
  • Fix invalid HTML response for route-level RSC requests in deployment adapter (#​91541)
  • Patch setHeader for direct route handlers (#​93101)
  • Include deployment id in cacheHandlers keys (#​93453)
  • Fix double-encoding of URL pathname parts in client param parsing (#​93491)

v16.2.5

Compare Source

[!NOTE]
This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary.

Security Fixes

The following advisories have been addressed:

High:

Moderate:

Low:

Core Changes
  • fix: preserve HTTP access fallbacks during prerender recovery (#​92231)
  • Fix fallback route params case in app-page handler (#​91737)
  • Fix invalid HTML response for route-level RSC requests in deployment adapter (#​91541)
  • Patch setHeader for direct route handlers (#​93101)
  • Include deployment id in cacheHandlers keys (#​93453)
  • Fix double-encoding of URL pathname parts in client param parsing (#​93491)

v16.2.4

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • chore: Bump reqwest to 0.13.2 (Fixes Google Fonts with Turbopack for Windows on ARM64) (#​92713)
  • Turbopack: fix filesystem watcher config not applying follow_symlinks(false) (#​92631)
  • Scope Safari ?ts= cache-buster to CSS/font assets only (Pages Router) (#​92580)
  • Compiler: Support boolean and number primtives in next.config defines (#​92731)
  • turbo-tasks: Fix recomputation loop by allowing cell cleanup on error during recomputation (#​92725)
  • Turbopack: shorter error for ChunkGroupInfo::get_index_of (#​92814)
  • Turbopack: shorter error message for ModuleBatchesGraph::get_entry_index (#​92828)
  • Adding more system info to the 'initialize project' trace (#​92427)
Credits

Huge thanks to @​Badbird5907, @​lukesandberg, @​andrewimm, @​sokra, and @​mischnic for helping!

v16.2.3

Compare Source

[!NOTE]
This release is backporting security and bug fixes. For more information about the fixed security vulnerability, please see https://vercel.com/changelog/summary-of-cve-2026-23869. The release does not include all pending features/changes on canary.

Core Changes
  • Ensure app-page reports stale ISR revalidation errors via onRequestError (#​92282)
  • Fix [Bug]: manifest.ts breaks HMR in Next.js 16.2 (#​91981 through #​92273)
  • Deduplicate output assets and detect content conflicts on emit (#​92292)
  • Fix styled-jsx race condition: styles lost due to concurrent rendering (#​92459)
  • turbo-tasks-backend: stability fixes for task cancellation and error handling (#​92254)
Credits

Huge thanks to @​icyJoseph, @​sokra, @​wbinnssmith, @​eps1lon and @​ztanner for helping!

v16.2.2

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • backport: Move expanded adapters docs to API reference (#​92115) (#​92129)
  • Backport: TypeScript v6 deprecations for baseUrl and moduleResolution (#​92130)
  • [create-next-app] Skip interactive prompts when CLI flags are provided (#​91840)
  • next.config.js: Accept an option for serverFastRefresh (#​91968)
  • Turbopack: enable server HMR for app route handlers (#​91466)
  • Turbopack: exclude metadata routes from server HMR (#​92034)
  • Fix CI for glibc linux builds
  • Backport: disable bmi2 in qfilter #​92177
  • [backport] Fix CSS HMR on Safari (#​92174)
Credits

Huge thanks to @​nextjs-bot, @​icyJoseph, @​ijjk, @​gaojude, @​wbinnssmith, @​lukesandberg, and @​bgw for helping!

v16.2.1

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • docs: post release amends (#​91715)
  • docs: fix broken Activity Patterns demo link in preserving UI state guide (#​91698)
  • Fix adapter outputs for dynamic metadata routes (#​91680)
  • Turbopack: fix webpack loader runner layer (#​91727)
  • Fix server actions in standalone mode with cacheComponents (#​91711)
  • turbo-persistence: remove Unmergeable mmap advice (#​91713)
  • Fix layout segment optimization: move app-page imports to server-utility transition (#​91701)
  • Turbopack: lazy require metadata and handle TLA (#​91705)
  • [turbopack] Respect {eval:true} in worker_threads constructors (#​91666)
Credits

Huge thanks to @​icyJoseph, @​abhishekmardiya, @​ijjk, @​mischnic, @​unstubbable, @​sokra, and @​lukesandberg for helping!

v16.2.0

Compare Source

[!TIP]
Check out our Next v16.2 Blog Post to learn more about this release.

Core Changes
  • Upgrade React from f93b9fd4-20251217 to 65eec428-20251218: #​87323
  • Turbopack: Create junction points instead of symlinks on Windows: #​87606
  • Turbopack: Symlink handling follow-up: #​87637
  • Add experimental routing package for resolving adapter routes: #​86404
  • Ensure outputs are correct with cache components in deployment adapters: #​87018
  • Move off of deprecated url.parse: #​87257
  • [strict-route-types] Add experimental.strictRouteTypes config: #​87378
  • misc: fix type check log for CI envs: #​87838
  • fix: revalidateTag with profile should not trigger client cache invalidation: #​88069
  • chore: warn when running tests against stale build: #​88001
  • Redesign default error pages with cleaner, more user-friendly UI: #​87988
  • dx: avoid next-env.d.ts change in dev: #​88103
  • prevent browser cache from using stale RSC responses from previous builds: #​86554
  • [strict-route-types] Typecheck App Router page props: #​87386
  • [strict-route-types] Enforce common React Component return types in App Router: #​87389
  • [strict-route-types] Switch to satisfies when validating page and route modules: #​87398
  • [strict-route-types] Don't reject number in config.api.bodyParser.sizeLimit when validating route: #​87633
  • Revert "dx: avoid next-env.d.ts change in dev": #​88153
  • [strict-route-types] Typecheck pages router routes in absence of App Router: #​87628
  • [strict-route-types] Ensure cache profiles and routes are type-checked even if .next is excluded: #​87768
  • add compilation error for taint when not enabled: #​88173
  • feat(next/image)!: add images.maximumResponseBody config: #​88183
  • Add maximum size limit for postponed body parsing: #​88175
  • metadata: use fixed segment in dynamic routes with static metadata files: #​88113
  • feat: add --experimental-cpu-prof flag for dev, build, and start: #​87946
  • Add experimental option to use no-cache instead of no-store in dev: #​88182
  • fix overlay frames cannot be opened sometimes: #​88210
  • Handle pnpm-workspace.yaml while searching for monorepo root: #​74818
  • Add more debug logs to 'use cache' wrapper: #​88219
  • Omit unused arguments from 'use cache' function calls: #​86920
  • Only log pending revalidates... debug log if applicable: #​88221
  • fix(next/image): bump sharp@​0.34.5: #​88238
  • Disallow javascript urls in router methods and redirects: #​88185
  • Fix relative same host redirects in node middleware: #​88253
  • Remove loadConfig from main development process, pass value from child process: #​88230
  • Update deploy adapters outputs and handler interfaces for node and edge: #​88247
  • Move Ready in time before handler initialization: #​88235
  • next/image: support custom cache handlers: #​88248
  • feat: add Claude Code plugin marketplace with Cache Components skill: #​87993
  • refactor: consolidate PPR into cacheComponents architecture: #​88243
  • Turbopack: include fewer traced files for standalone: #​88322
  • feat(turbopack): add resolve plugin condition variant of Always and Never: #​88190
  • perf: use length = 0 to clear the logging array: #​88244
  • Time logs: Show full millisecond instead of 1 decimal: #​88313
  • [turbopack] Enable inferring module side effects by default: #​87216
  • Track search string as part of "refresh state": #​87203
  • Pass RouteTree into navigation function: #​87256
  • Read from segment cache unknown routes: #​87293
  • Pass loading boundary as part of RSC data: #​87825
  • Revert "refactor: consolidate PPR into cacheComponents architecture (#​88243)": #​88421
  • fix: support TypeScript noUncheckedSideEffectImports for CSS imports: #​88199
  • Don't import typescript at runtime: #​88321
  • fix: use RDC for server action requests: #​88129
  • Warn when overriding Cache-Control header on /_next/ routes: #​88353
  • [prebuilt-skew-protection] feat: adding in automatic deploymentId: #​88012
  • Revert "[prebuilt-skew-protection] feat: adding in automatic deploymentId": #​88449
  • Turbopack: Update reqwest, remove experimental system TLS feature: #​88290
  • Revert "prevent browser cache from using stale RSC responses from pre…: #​88457
  • Turbopack: retain loader tree order for metadata: #​88487
  • Turbopack: more dead code: #​88505
  • fix(build): prevent route handler manifests from inheriting unrelated client components: #​88419
  • Upgrade React from 65eec428-20251218 to 3e1abcc8-20260113: #​88530
  • Better typesafety for interopDefault: #​88486
  • keep next-env.d.s unchanged between dev and build: #​88428
  • Remove sibling caches from CacheNode tree: #​87991
  • Upgrade React from 3e1abcc8-20260113 to 4a3d993e-20260114: #​88547
  • Finish deleting Mutable from router implementation: #​88046
  • fetch(next/image): reduce maximumResponseBody from 300MB to 50MB: #​88588
  • [CC] Fix dev validation error from server action bound args: #​88600
  • Fix incorrect 'Ready in' time for next start: #​88589
  • feat: server action logging: #​88277
  • Log browser error and warnings in terminal: #​88352
  • Upgrade React from 4a3d993e-20260114 to bef88f7c-20260116: #​88649
  • fix: make RedirectType constant properties literal types: #​88653
  • Turbopack: add support for matching loaders on resource queries: #​88644
  • fix: capture promisified setImmediate separately: #​88346
  • fix: setImmediate[util.promisify.custom] access fails in edge runtime: #​88685
  • Fix --debug-build-paths bracket escaping for glob patterns: #​88660
  • Add negation pattern support to --debug-build-paths: #​88654
  • Only filter next config if experimental flag is enabled: #​88733
  • [Devtool Indicator] Fix cross alignment: #​88664
  • Turbopack: don't use build id for pages router client-side manifests: #​88641
  • Allow inspecting server with next start --inspect: #​88744
  • Turbopack: Add --debug-build-paths support to filter routes: #​88655
  • Upgrade React from bef88f7c-20260116 to 41b3e9a6-20260119: #​88756
  • Use rewritten pathname for implicit cache tags: #​88732
  • Upgrade React from 41b3e9a6-20260119 to d2908752-20260119: #​88774
  • Add experimental_gesturePush to App Router: #​88776
  • Rename rewroteURL to rewrittenPathname in request metadata: #​88751
  • Simplify getImplicitTags to accept pathname instead of url object: #​88753
  • Add NEXT_DEPLOYMENT_ID global: #​86738
  • Turbopack: remove deployment id suffix from client reference manifest chunks: #​88741
  • Inject <html data-dpl-id> and don't inline it into JS anymore: #​88761
  • [metadata] match the Metadata and ResolvedMetadata type: #​88739
  • Reuse bfcache data during Full prefetches: #​88606
  • Embed static sibling info in route tree: #​88692
  • Fix revalidatePath with params and trailing slash when deployed: #​88623
  • fix: preserve cache behavior for PPR fallback shells with root params: #​88556
  • Upgrade React from d2908752-20260119 to b546603b-20260121: #​88860
  • stabilize browser log forward options: #​88857
  • [devtools] Wrap long file names of stack frames in the error overlay: #​88886
  • [devtools] Fix notch coloring of error overlay in forced colors mode: #​88892
  • Remove deploymentId from App Router RenderOptsPartial: #​88866
  • feat: implement LRU cache with invocation ID scoping for minimal mode response cache: #​88509
  • [prebuilt-skew-protection] feat: adding in automatic deploymentId: #​88496
  • [devtool] Add hydration diff indicator for diff lines: #​88919
  • Revert "[prebuilt-skew-protection] feat: adding in automatic deploymentId": #​88942
  • [turbopack] add task type infromation to the print_cache_item_size feature: #​88925
  • Upgrade React from b546603b-20260121 to 24d8716e-20260123: #​88963
  • Turbopack: add ?dpl= to all asset urls returned by Turbopack: #​88828
  • feat(next-codemod): add agents-md command for AI coding agents: #​88961
  • Update font data: #​88975
  • Improve agents-md prompt to force doc retrieval: #​88997
  • [Reapply] Add useEffectEvent to disallowed React APIs in Server Components: #​88985
  • Apply fixes for onBuildComplete and route module: #​88831
  • Rename renderOpts.nextExport to isBuildTimePrerendering: #​88951
  • docs: fix typos in README.mds: #​89022
  • refactor: consume global-error from loader tree: #​88437
  • Fix chunk loading when using __turbopack_load_by_url__ with query: #​88899
  • [mcp] change the mcp endpoint response to JSON: #​88911
  • Reapply "[turbopack] Add bundling support for worker_threads" (#​88725): #​88967
  • fix: ensure LRU cache items have minimum size of 1 to prevent unbounded growth: #​89040
  • Upgrade React from 24d8716e-20260123 to 8c34556c-20260126: #​89066
  • Use null-prototype objects in server actions manifests: #​89069
  • Re-enable types-and-precompiled: #​89070
  • Apply segment changes to adapters outputs: #​89072
  • Improve no response route handler error: #​89036
  • Limit number of server action arguments to 1000: #​89068
  • [prebuilt-skew-protection] feat: adding in automatic deploymentId: #​88958
  • Decouple route stale time from segment-level data: #​88834
  • Decouple route and segment cache lifecycles: #​88989
  • [ci] Silence baseline-browser-mapping warnings: #​89175
  • [Cache Components] Prevent streaming fetch calls from hanging in dev: #​89171
  • React types update: #​89110
  • [nextjs] feat: removing length requirement: #​89173
  • add GPTBot to matcher for known bots: #​89188
  • Ensure .md licenses are included in vendored packages: #​89201
  • Switch development log item format as JSON: #​89168
  • IsolatedDevBuild flag removal: #​89167
  • fix: coerce HEAD to GET for internal images: #​84180
  • Upgrade React from 10680271-20260126 to 230772f9-20260128: #​89250
  • Upgrade tar used to extract SWC binary : #​89158
  • Sort prerender manifest routes: #​89246
  • Track vary params for segments without server-side param access: #​88998
  • Optimistic routing: client-side route prediction: #​88965
  • Keep pages/404.js to be able to dynamically render it anyway: #​89263
  • fix: fully static pages should emit & serve static rsc payloads: #​89202
  • fix: CSRF origin matching should be case-insensitive: #​89127
  • fix(build): format runAfterProductionCompile duration as human-readable time: #​89232
  • fix(router): support BigInt in query parameters: #​89213
  • Update font data: #​89200
  • Update font data: #​89272
  • Turbopack: add support for contentType condition for webpack loaders: #​89156
  • Revert "fix(router): support BigInt in query parameters": #​89283
  • Track vary params during static prerendering: #​89267
  • Improve lock dir error message: #​89119
  • Ensures browserslist doesn't issue outdated warnings for baseline-browser-mapping: #​89287
  • Replace build id in Pages data routes with deployment id: #​88959
  • Upgrade React from 230772f9-20260128 to da641178-20260129: #​89301
  • Inline handler dependencies instead of tracing: #​89269
  • Turbopack: add rules.*.type config to allow changing the type of a module: #​88788
  • Add experimental.varyParams feature flag: #​89307
  • Fix/zlib mem node: #​89099
  • Revert "Replace build id in Pages data routes with deployment id (#​88959)": #​89323
  • Turbopack: Rename crates/napi to crates/next-napi-bindings and update crate name: #​89314
  • feat: detect @​typescript/native-preview as alternative TypeScript compiler: #​89149
  • Revert "Fix/zlib mem node": #​89322
  • Turbopack: FreeVarReference::ReportUsage: #​89302
  • Make Server Function logging opt-in via logging.serverFunctions: #​89321
  • Restore default-enabled Server Function logging: #​89407
  • Re-add build-complete traces for webpack: #​89402
  • Skip Server Function logging for 'use cache' functions: #​89408
  • Replace flight navigation build id field with header: #​88855
  • Upgrade React from da641178-20260129 to ed4bd540-20260202: #​89401
  • Upgrade React from ed4bd540-20260202 to b1533b03-20260203: #​89444
  • Upgrade React from b1533b03-20260203 to 3e00319b-20260203: #​89449
  • Rename CACHE_ONE_YEAR for clarity and fix usage: #​89450
  • [Codemod] Fix agents-md on Windows: #​89319
  • Experimental deferred entries handling: #​88347
  • Add experimental.reportSystemEnvInlining for Turbopack: #​89304
  • fix: use signal-based exit codes to prevent inspector blocking exit: #​89351
  • Add Instant Navigation Testing API: #​89465
  • Support MPA navigations in instant(): #​89469
  • Handle Pages data route skew with deployment id header, take 2: #​89325
  • Include owner stack for forwarded errors if available: #​89493
  • [CC] Rename "unstable_prefetch" to "unstable_instant": #​89448
  • Ensure module contexts are always included in adapter traces: #​89508
  • Don't insert build id comment in HTML: #​89478
  • Clarify type checking error message: #​89525
  • Require explicit cacheLife on outer "use cache" when nesting short-lived caches: #​89481
  • [Instant] Instant validation in Dev: #​89077
  • Upgrade React from 3e00319b-20260203 to 95ffd6cd-20260205: #​89550
  • Turbpopack: fix is_persistent_caching_enabled: #​89533
  • Fix a small doc typo: #​89553
  • Ensure _middleware is consistent in adapter for name/id: #​89559
  • Ensure Errors with deep causal chains respect inspect depth: #​89594
  • refactor: extract route discovery into unified discoverRoutes() API: #​88971
  • Ensure static metadata are static outputs for adapters: #​89574
  • Resolve local variable references in error code SWC plugin: #​89596
  • Turbopack: Add --experimental-server-fast-refresh CLI flag: #​89274
  • Fix deployment id header when proxying: #​89593
  • fix: deprecated util._extend: #​89614
  • Fix missing non-deferred turbopack build items: #​89616
  • Revert "Ensure _middleware is consistent in adapter for name/id": #​89624
  • Omit unused arguments for server actions: #​89651
  • Upgrade React from 95ffd6cd-20260205 to 2dd9b7cf-20260208: #​89681
  • Include AggregateError.errors in terminal output: #​88999
  • fix(image): findClosestQuality returns 0 for low quality values: #​89621
  • Upgrade React from 2dd9b7cf-20260208 to 272441a9-20260209: #​89722
  • Avoid using unclosing prefetch streams in the browser: #​89610
  • Pass shouldCache to all manifest loading calls: #​89713
  • Add 2nd cloned body to FinalizationRegistry. Only used RuntimeStyles component for webpack: #​88577
  • Tracing: trace render times as render-path: #​89763
  • Turbopack: Server HMR infrastructure: #​88870
  • Turbopack: Reorganize runtime files into shared/runtime directory: #​89461
  • [Instant] Validation on client navs: #​89777
  • Turbopack: extract core hmr client logic into shared runtime: #​88912
  • Turbopack: Fix slow filesystem benchmark warning for next dev: #​89798
  • Add turbopackIgnoreIssue config to suppress Turbopack warnings: #​89682
  • Add support for with type: "text" under a new experimental flag, following what webpack did: #​89560
  • Remove unused devtools code handling React without use: #​89793
  • [devtools] Wrap overlay in Activity: #​89818
  • Add CSS URL deployment ID suffix support: #​89771
  • Fix cascading LRU eviction during prefetch batches: #​89766
  • Refactor prerenderManifest passing: #​89765
  • [AI] Ship bundled docs in next and generate AGENTS.md in create-next-app: #​89850
  • Turbopack: Implement server hmr in nodejs dev runtime: #​89130
  • Allow sitemap.ts and sitemap/page.tsx to coexist in Turbopack: #​89789
  • [fragment-scroll] Cleanup scroll and focus restoration in layout router: #​83110
  • [fragment-scroll] Add experimental.appNewScrollHandler: #​83107
  • [Instant] Fix crash with search params: #​89922
  • Fix memory leak in dev mode caused by fast-set-immediate: #​89779
  • Trace upload: include experimental flag states: #​89845
  • Upgrade React from 272441a9-20260209 to 6066c782-20260212: #​89923
  • Add a better error message for when turbopack cannot be loaded: #​89633
  • fix: support multiple icon formats with same base name (icon.png + icon.svg): #​89504
  • Turbopack: Move turbopackIgnoreIssue from experimental to turbopack.ignoreIssue: #​89817
  • Build with dev runtimes when --debug-prerender is set: #​89834
  • Append deployment id query string for next-font: #​89960
  • Fix parallel routes with deferred entries: #​89967
  • Rename node extension utils for clarity: #​89970
  • Model abandoning by signal: #​89971
  • Fix missing incremental cache in middleware unstable_cache: #​89980
  • Run fast immediates during prerender abort to fix flaky I/O stack traces: #​89969
  • [fragment-scroll] Ensure hoisted elements don't break scroll-to-top on page navigations: #​83108
  • dx: Include path count in export error message: #​89333
  • fix(agents-md): use require.resolve() to get the installed next version: #​89166
  • docs: agent skills, pr-status script, and AGENTS.md updates (1/8): #​89857
  • Ignore prefetch={true} on Links to routes with instant: #​90061
  • Expand deferred entries test suite and fix turbopack build: #​90057
  • Use StageController for runtime prerendering: #​89972
  • Improve task pipelining: #​90065
  • fix(next/legacy/image): add deployment id (dpl) query string support: #​89956
  • Cache expected missing manifest read: #​89908
  • Use for...in instead of Object.keys for parallelRouteKey traversal: #​89905
  • [Instant] allow non-blocking dynamic holes and errors in shared parents: #​89875
  • Move prefetch hints from CacheNodeSeedData to FlightRouterState: #​90066
  • [Instant] Don't block on client APIs that wouldn't block in the browser: #​89924
  • [devtools] Add support for error causes in the dev overlay: #​90108
  • Unify runInSequentialTasks across all sequential task work: #​89978
  • Cleanup all stage promises on abort: #​89984
  • segment cache: fix segment cache normalizer: #​90111
  • Handle null history.state in client-side router popstate handler: #​90083
  • Don't parse default postponedsizelimit: #​89906
  • Turbopack: handle invalid RSC imports via importmap: #​88146
  • [create-next-app] Improve AGENTS.md prompt wording: #​90118
  • ensure maxPostponedStateSize is always respected: #​90060
  • Upgrade React from 6066c782-20260212 to 4842fbea-20260217: #​90144
  • [fragment-scroll] Stop focusing the first focusable host descendant: #​89903
  • fix: normalize loopback only in hostname: #​90158
  • Only error for sync IO after runtime in segments that would be runtime prefetched: #​89979
  • [refactor] Replace runtime prefetch sentinel transform stream: #​90160
  • fix: use Buffer.indexOf in uint8array helpers for faster byte scanning (3/8): #​89864
  • Automatically build and clear native build when running pnpm build: #​89819
  • fix(cache): DCE to avoid pulling server internals into browser bundles (4/8): #​89865
  • Attach active src route to next global: #​90171
  • Fix OTEL propagation and add direct entrypoint e2e coverage: #​90181
  • Use cookie as sole protocol for instant navigation testing: #​89871
  • Simplify metadata tag rendering to flat imperative style: #​90209
  • Prevent unhandled rejection filter from being bundled into the server runtime: #​90205
  • [Instant] speed up test instant-validation suite: #​90214
  • Turbopack: fix static asset skew protection for edge and prerenders: #​90238
  • Remove workStore from params/searchParams/pathname function signatures: #​90215
  • Remove workStore from metadata resolution chain: #​90217
  • [Instant] export "Instant" config type: #​90257
  • Replace getDynamicParamFromSegment closure with interpolatedParams in metadata: [#​90249](https://redire

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Greptile Summary

This PR bumps next and @next/eslint-plugin-next from 16.1.6 to 16.2.10 across the monorepo catalog and updates the lockfile accordingly. The upgrade spans several patch releases that include critical security fixes.

  • Security patches in 16.2.5/16.2.6: Multiple high-severity advisories are resolved, including middleware/proxy bypass vulnerabilities (GHSA-267c-6grr-h53f, GHSA-492v-c6pp-mqqv, GHSA-36qx-fr4f-26g5), a Denial of Service in Server Components (GHSA-8h8q-6873-q5fj), and an SSRF in WebSocket upgrades (GHSA-c4j6-fc7j-m34r), plus moderate XSS and cache-poisoning issues.
  • Additional patches (16.2.7–16.2.10): Bug fixes for dev-mode hydration failures, FormData entry dropping, catch-all router.query corruption, and server action forwarding loops; 16.2.10 adds the previously missing @next/swc-wasm-web publish.

Confidence Score: 5/5

Safe to merge — this is a lockfile-only dependency upgrade with no application code changes.

The change is limited to version specifiers in pnpm-workspace.yaml and the generated pnpm-lock.yaml. It picks up a series of important security patches and bug fixes from the Next.js project. No application logic, configuration, or test files were modified. The two newly annotated deprecated notices in the lockfile (stream-to-promise, tsconfck) are pre-existing indirect dependencies whose deprecation status is unrelated to this bump.

No files require special attention.

Reviews (1): Last reviewed commit: "Update nextjs monorepo to v16.2.10" | Re-trigger Greptile

@amitsingh-007
amitsingh-007 enabled auto-merge (squash) July 8, 2026 16:34
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Bump Next.js and @next/eslint-plugin-next to 16.2.10 (pnpm monorepo)

⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Bump Next.js runtime from 16.1.6 to 16.2.10 across the pnpm workspace.
• Update @next/eslint-plugin-next to 16.2.10 to keep lint rules aligned.
• Refresh pnpm lockfile to reflect new Next/SWC artifacts and resolved metadata.
Diagram

graph TD
  E["Monorepo packages"] --> A["pnpm-workspace.yaml"] --> B["pnpm-lock.yaml"] --> C["next@16.2.10"] --> F["Build/Dev runtime"]
  B --> D["@next/eslint-plugin-next@16.2.10"] --> G["Lint rules"]
Loading
High-Level Assessment

The PR follows the standard Renovate-driven upgrade path (update workspace catalog, refresh lockfile). No alternative approach is meaningfully better; reviewers should mainly validate CI (lint/build/tests) and watch for any Next.js 16.2.x behavioral changes or peer/engine constraints in downstream packages.

Files changed (2) +58 / -56

Other (2) +58 / -56
pnpm-lock.yamlRegenerate lockfile for Next.js 16.2.10 + updated SWC packages +56/-54

Regenerate lockfile for Next.js 16.2.10 + updated SWC packages

• Updates the resolved Next.js dependency tree from 16.1.6 to 16.2.10, including platform-specific @next/swc artifacts and integrity hashes. Also reflects metadata changes surfaced during resolution (e.g., new deprecation annotations for some transitive packages).

pnpm-lock.yaml

pnpm-workspace.yamlBump workspace catalog pins for next and @next/eslint-plugin-next +2/-2

Bump workspace catalog pins for next and @next/eslint-plugin-next

• Updates the pnpm workspace catalog entries to pin next and @next/eslint-plugin-next at 16.2.10 so all workspaces consume the same versions.

pnpm-workspace.yaml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 22 rules

Grey Divider


Remediation recommended

1. Missing Node engine constraint 🐞 Bug ☼ Reliability
Description
next@16.2.10 requires Node.js >=20.9.0, but the repo doesn’t declare a supported Node version via
package.json#engines, so installs/builds may succeed in CI (Node 24) but fail in other
environments running older Node. This can cause hard-to-diagnose build/deploy failures depending on
the developer or deployment runtime.
Code

pnpm-lock.yaml[R5736-5738]

+  next@16.2.10:
+    resolution: {integrity: sha512-2som5AVXb3kE6Yjine3/mNbBayYF58eguBWIVVUdr1y/L426xyVEgYxgBG+1QC34P2x5E+tcDup6XkuOAX3dCA==}
    engines: {node: '>=20.9.0'}
Relevance

⭐⭐ Medium

No historical evidence found of team adding/enforcing package.json engines for Node compatibility
constraints.

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The lockfile shows next@16.2.10 has an engine requirement of Node >=20.9.0, while the repo root
package.json has no engines declaration. CI uses Node 24, meaning it won’t catch issues that
occur on older Node versions.

pnpm-lock.yaml[5736-5739]
package.json[1-34]
.github/workflows/build.yml[20-28]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`next@16.2.10` enforces a minimum Node version (>=20.9.0) but the repo does not declare this requirement, allowing unsupported Node versions in local/dev/deploy environments.

### Issue Context
CI pins Node `24`, so this mismatch may not be caught until someone runs the project elsewhere.

### Fix Focus Areas
- package.json[1-34]
- pnpm-lock.yaml[5736-5739]
- .github/workflows/build.yml[20-28]

### Suggested fix
- Add an explicit Node engine constraint in the root `package.json`, e.g.:
 - `"engines": { "node": ">=20.9.0" }` (or align to your desired supported range)
- Optionally add `.nvmrc` / documentation so local dev matches CI.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Informational

2. Unmaintained tsconfck dependency 🐞 Bug ⚙ Maintainability
Description
The lockfile marks tsconfck@3.1.6 as deprecated/unmaintained, and it is pulled in via
vite-tsconfig-paths which is used by the extension app tooling. This creates upgrade risk because
the project depends on an unmaintained package in an active build/dev path.
Code

pnpm-lock.yaml[R6943-6947]

  tsconfck@3.1.6:
    resolution: {integrity: sha512-ks6Vjr/jEw0P1gmOVwutM3B7fWxoWBL2KRDb1JfqGVawBmO5UsvmWOQFGHBPl5yxYz4eERr19E6L7NMv+Fej4w==}
    engines: {node: ^18 || >=20}
+    deprecated: unmaintained
    hasBin: true
Relevance

⭐ Low

Similar lockfile deprecation/upgrade suggestions were rejected in PR #3812; team appears to ignore
lockfile deprecation flags.

PR-#3812

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The lockfile explicitly labels tsconfck@3.1.6 as deprecated/unmaintained. The same lockfile shows
vite-tsconfig-paths depends on tsconfck, and apps/extension declares vite-tsconfig-paths as
a dev dependency (so this affects an active toolchain).

pnpm-lock.yaml[6943-6947]
pnpm-lock.yaml[14471-14476]
apps/extension/package.json[44-57]
pnpm-workspace.yaml[68-75]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`tsconfck` is marked deprecated/unmaintained and is included via `vite-tsconfig-paths`, which is used by `apps/extension`.

### Issue Context
This won’t necessarily break immediately, but it increases long-term maintenance risk for the extension build pipeline.

### Fix Focus Areas
- pnpm-lock.yaml[6943-6947]
- pnpm-lock.yaml[14471-14476]
- pnpm-workspace.yaml[68-75]
- apps/extension/package.json[44-57]

### Suggested fix
- Check if a newer `vite-tsconfig-paths` version eliminates `tsconfck`, and bump `vite-tsconfig-paths` in the catalog (`pnpm-workspace.yaml`).
- If not possible, consider an alternative tsconfig-paths solution for Vite (or pin/patch) to remove reliance on an unmaintained parser.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Comment thread pnpm-lock.yaml
Comment on lines +5736 to 5738
next@16.2.10:
resolution: {integrity: sha512-2som5AVXb3kE6Yjine3/mNbBayYF58eguBWIVVUdr1y/L426xyVEgYxgBG+1QC34P2x5E+tcDup6XkuOAX3dCA==}
engines: {node: '>=20.9.0'}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Missing node engine constraint 🐞 Bug ☼ Reliability

next@16.2.10 requires Node.js >=20.9.0, but the repo doesn’t declare a supported Node version via
package.json#engines, so installs/builds may succeed in CI (Node 24) but fail in other
environments running older Node. This can cause hard-to-diagnose build/deploy failures depending on
the developer or deployment runtime.
Agent Prompt
### Issue description
`next@16.2.10` enforces a minimum Node version (>=20.9.0) but the repo does not declare this requirement, allowing unsupported Node versions in local/dev/deploy environments.

### Issue Context
CI pins Node `24`, so this mismatch may not be caught until someone runs the project elsewhere.

### Fix Focus Areas
- package.json[1-34]
- pnpm-lock.yaml[5736-5739]
- .github/workflows/build.yml[20-28]

### Suggested fix
- Add an explicit Node engine constraint in the root `package.json`, e.g.:
  - `"engines": { "node": ">=20.9.0" }` (or align to your desired supported range)
- Optionally add `.nvmrc` / documentation so local dev matches CI.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

@amitsingh-007
amitsingh-007 merged commit e5060d2 into renovate-updates Jul 8, 2026
3 checks passed
@amitsingh-007
amitsingh-007 deleted the renovate/nextjs-monorepo branch July 8, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant