Skip to content

Upgrade Next.js to 16.3.8 (critical RCE advisories) - #3

Merged
ralyodio merged 1 commit into
mainfrom
next-16.3.8
Oct 1, 2026
Merged

ralyodio merged 1 commit into
mainfrom
next-16.3.8

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps next 16.3.0 -> 16.3.8 (and the app version to 0.1.1 for the patch release) to close:

React and everything else untouched. bun.lock moves only next and its own dependencies (@next/env, @next/swc-*, @swc/helpers).

Verified locally:

  • bun install --frozen-lockfile, bun run test (9 pass), bun run typecheck, bun run build all clean
  • Booted the standalone output with bun server.js (the image CMD) and compared with live launch.anapp.now: /, /privacy, /healthz, /robots.txt, /sitemap.xml 200 with the same title; /opengraph-image and /twitter-image 200 image/png; a /_next/image?url=...&w=256&q=75 URL 200 image/png, identical size to live.

🤖 Generated with Claude Code

next 16.3.0 -> 16.3.8 for GHSA-vcvr-r3jv-pc5j, GHSA-2xp9-vwfh-vxw4 and
GHSA-p293-qw3h-jr36. Lockfile moves only next and its own dependencies
(@next/env, @next/swc-*, @swc/helpers). Version 0.1.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​16.3.0 ⏵ 16.3.861100 +7590 +19970

View full report

@ralyodio
ralyodio merged commit b01eaee into main Oct 1, 2026
3 checks passed
@ralyodio
ralyodio deleted the next-16.3.8 branch October 1, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant