Repository navigation
Update nextjs monorepo to v16.2.10 - #4038
Conversation
PR Summary by QodoBump Next.js and @next/eslint-plugin-next to 16.2.10 (pnpm monorepo)
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Code Review by Qodo
1. Missing Node engine constraint
|
| next@16.2.10: | ||
| resolution: {integrity: sha512-2som5AVXb3kE6Yjine3/mNbBayYF58eguBWIVVUdr1y/L426xyVEgYxgBG+1QC34P2x5E+tcDup6XkuOAX3dCA==} | ||
| engines: {node: '>=20.9.0'} |
There was a problem hiding this comment.
1. Missing node engine constraint 🐞 Bug ☼ Reliability
next@16.2.10 requires Node.js >=20.9.0, but the repo doesn’t declare a supported Node version via package.json#engines, so installs/builds may succeed in CI (Node 24) but fail in other environments running older Node. This can cause hard-to-diagnose build/deploy failures depending on the developer or deployment runtime.
Agent Prompt
### Issue description
`next@16.2.10` enforces a minimum Node version (>=20.9.0) but the repo does not declare this requirement, allowing unsupported Node versions in local/dev/deploy environments.
### Issue Context
CI pins Node `24`, so this mismatch may not be caught until someone runs the project elsewhere.
### Fix Focus Areas
- package.json[1-34]
- pnpm-lock.yaml[5736-5739]
- .github/workflows/build.yml[20-28]
### Suggested fix
- Add an explicit Node engine constraint in the root `package.json`, e.g.:
- `"engines": { "node": ">=20.9.0" }` (or align to your desired supported range)
- Optionally add `.nvmrc` / documentation so local dev matches CI.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
This PR contains the following updates:
16.1.6→16.2.1016.1.6→16.2.10Release Notes
vercel/next.js (@next/eslint-plugin-next)
v16.2.10Compare Source
Contains no changes except publishing
@next/swc-wasm-webwhich was accidentally not published since 16.2.4.v16.2.9Compare Source
Empty release to ensure
next@latestpoints at a stable release. Next.js only allows publishing with Trusted Publishing enabled. In order to fix NPM dist-tags, we have to release a new version. Updating dist-tags is not possible with Trusted Publishing.v16.2.8Compare Source
Release with no changes in an attempt to fix
next@latestpointing at a prerelease version.v16.2.7Compare Source
Core Changes
playwright-coreto resolve_finishedPromiseonrequestFailed(#93920)router.querycorruption withbasePath+rewrites(#93917)FormDataentries (#94240)Credits
Huge thanks to @eps1lon, @icyJoseph, @unstubbable, @mischnic, @bgw, @timneutkens, and @lukesandberg for helping!
v16.2.6Compare Source
Security Fixes
The following advisories have been addressed:
High:
Moderate:
Low:
Core Changes
cacheHandlerskeys (#93453)v16.2.5Compare Source
Security Fixes
The following advisories have been addressed:
High:
Moderate:
Low:
Core Changes
cacheHandlerskeys (#93453)v16.2.4Compare Source
Core Changes
Credits
Huge thanks to @Badbird5907, @lukesandberg, @andrewimm, @sokra, and @mischnic for helping!
v16.2.3Compare Source
Core Changes
Credits
Huge thanks to @icyJoseph, @sokra, @wbinnssmith, @eps1lon and @ztanner for helping!
v16.2.2Compare Source
Core Changes
Credits
Huge thanks to @nextjs-bot, @icyJoseph, @ijjk, @gaojude, @wbinnssmith, @lukesandberg, and @bgw for helping!
v16.2.1Compare Source
Core Changes
cacheComponents(#91711){eval:true}in worker_threads constructors (#91666)Credits
Huge thanks to @icyJoseph, @abhishekmardiya, @ijjk, @mischnic, @unstubbable, @sokra, and @lukesandberg for helping!
v16.2.0Compare Source
Core Changes
f93b9fd4-20251217to65eec428-20251218: #87323experimental.strictRouteTypesconfig: #87378satisfieswhen validating page and route modules: #87398numberinconfig.api.bodyParser.sizeLimitwhen validating route: #87633images.maximumResponseBodyconfig: #88183'use cache'wrapper: #88219'use cache'function calls: #86920pending revalidates...debug log if applicable: #88221noUncheckedSideEffectImportsfor CSS imports: #88199/_next/routes: #8835365eec428-20251218to3e1abcc8-20260113: #88530interopDefault: #884863e1abcc8-20260113to4a3d993e-20260114: #885474a3d993e-20260114tobef88f7c-20260116: #88649--debug-build-pathsbracket escaping for glob patterns: #88660--debug-build-paths: #88654next start --inspect: #88744--debug-build-pathssupport to filter routes: #88655bef88f7c-20260116to41b3e9a6-20260119: #8875641b3e9a6-20260119tod2908752-20260119: #88774rewroteURLtorewrittenPathnamein request metadata: #88751getImplicitTagsto accept pathname instead of url object: #88753NEXT_DEPLOYMENT_IDglobal: #86738<html data-dpl-id>and don't inline it into JS anymore: #88761revalidatePathwith params and trailing slash when deployed: #88623d2908752-20260119tob546603b-20260121: #88860deploymentIdfrom App RouterRenderOptsPartial: #88866b546603b-20260121to24d8716e-20260123: #88963?dpl=to all asset urls returned by Turbopack: #88828useEffectEventto disallowed React APIs in Server Components: #88985renderOpts.nextExporttoisBuildTimePrerendering: #88951README.mds: #89022__turbopack_load_by_url__with query: #8889924d8716e-20260123to8c34556c-20260126: #89066baseline-browser-mappingwarnings: #89175.mdlicenses are included in vendored packages: #8920110680271-20260126to230772f9-20260128: #89250tarused to extract SWC binary : #89158browserslistdoesn't issue outdated warnings forbaseline-browser-mapping: #89287230772f9-20260128toda641178-20260129: #89301rules.*.typeconfig to allow changing the type of a module: #88788logging.serverFunctions: #89321'use cache'functions: #89408da641178-20260129toed4bd540-20260202: #89401ed4bd540-20260202tob1533b03-20260203: #89444b1533b03-20260203to3e00319b-20260203: #89449experimental.reportSystemEnvInliningfor Turbopack: #89304instant(): #89469cacheLifeon outer"use cache"when nesting short-lived caches: #894813e00319b-20260203to95ffd6cd-20260205: #89550discoverRoutes()API: #8897195ffd6cd-20260205to2dd9b7cf-20260208: #89681AggregateError.errorsin terminal output: #889992dd9b7cf-20260208to272441a9-20260209: #89722next dev: #89798type: "text"under a new experimental flag, following what webpack did: #89560use: #89793experimental.appNewScrollHandler: #83107272441a9-20260209to6066c782-20260212: #89923--debug-prerenderis set: #89834require.resolve()to get the installednextversion: #89166prefetch={true}on Links to routes withinstant: #900616066c782-20260212to4842fbea-20260217: #90144pnpm build: #89819Configuration
📅 Schedule: (UTC)
* 0-3 1 * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.
Greptile Summary
This PR bumps
nextand@next/eslint-plugin-nextfrom16.1.6to16.2.10across the monorepo catalog and updates the lockfile accordingly. The upgrade spans several patch releases that include critical security fixes.FormDataentry dropping, catch-allrouter.querycorruption, and server action forwarding loops; 16.2.10 adds the previously missing@next/swc-wasm-webpublish.Confidence Score: 5/5
Safe to merge — this is a lockfile-only dependency upgrade with no application code changes.
The change is limited to version specifiers in
pnpm-workspace.yamland the generatedpnpm-lock.yaml. It picks up a series of important security patches and bug fixes from the Next.js project. No application logic, configuration, or test files were modified. The two newly annotateddeprecatednotices in the lockfile (stream-to-promise,tsconfck) are pre-existing indirect dependencies whose deprecation status is unrelated to this bump.No files require special attention.
Reviews (1): Last reviewed commit: "Update nextjs monorepo to v16.2.10" | Re-trigger Greptile