Skip to content

Upgrade Next.js to 16.3.8 (critical RCE advisories) - #12

Merged
ralyodio merged 1 commit into
mainfrom
next-16.3.8
Oct 1, 2026
Merged

ralyodio merged 1 commit into
mainfrom
next-16.3.8

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Pins next in apps/web from ^16.0.10 (locked at 16.3.1) to exactly 16.3.8 to close:

React and everything else untouched. bun.lock moves only next and its own dependencies (@next/env, @next/swc-, sharp + @img/sharp-).

Verified locally:

  • bun install --frozen-lockfile clean, apps/web tsc --noEmit clean, bun run build clean
  • bun test against a throwaway local Postgres 17: 115 pass
  • Booted the gateway the way the image runs it (bun apps/gateway/src/index.ts, web+api+media) against that local DB, and compared with live bufferoverride.com: /health, /, /questions, /tags, /docs, /login, /v1/tags, /v1/questions, /sitemap.xml, /feed.xml, /media/health all 200, same titles. Next reports 16.3.8 at boot. The web app uses neither next/og nor next/image.

🤖 Generated with Claude Code

next ^16.0.10 (locked 16.3.1) -> 16.3.8 exact, for GHSA-vcvr-r3jv-pc5j,
GHSA-2xp9-vwfh-vxw4 and GHSA-p293-qw3h-jr36. Lockfile moves only next and
its own dependencies (@next/env, @next/swc-*, sharp/@img/*).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​16.3.1 ⏵ 16.3.861100 +7590 +19970

View full report

@ralyodio
ralyodio merged commit 6bc91a3 into main Oct 1, 2026
4 checks passed
@ralyodio
ralyodio deleted the next-16.3.8 branch October 1, 2026 23:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant