Skip to content

[Snyk] Security upgrade next from 15.3.5 to 16.3.0 - #33

Open
RealSollyM wants to merge 1 commit into
mainfrom
snyk-fix-dbca91c03388ae8a19cc06405c529261
Open

RealSollyM wants to merge 1 commit into
mainfrom
snyk-fix-dbca91c03388ae8a19cc06405c529261

Conversation

@RealSollyM

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Directory Traversal
SNYK-JS-POSTCSS-18313036
  ****  
high severity Directory Traversal
SNYK-JS-POSTCSS-18313038
  ****  
medium severity Directory Traversal
SNYK-JS-POSTCSS-18512282
  ****  
medium severity Cross-site Scripting (XSS)
SNYK-JS-POSTCSS-16189065
  372  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)
🦉 Directory Traversal

@RealSollyM

Copy link
Copy Markdown
Contributor Author

Merge Risk: High

The upgrade from Next.js v15 to v16 is a major version jump that introduces significant breaking changes and requires a migration to React 19. Vercel provides a codemod to automate many of the required updates, indicating the complexity of the migration.

Key Breaking Changes:

  • React 19 Required: You must upgrade react and react-dom to the latest versions along with Next.js to avoid potential hydration errors.
  • Configuration Updates: The codemod automates changes to next.config.js for new Turbopack settings and updates the linting setup from next lint to the standard ESLint CLI.
  • API Stabilizations: The unstable_ prefix has been removed from several APIs that are now stable. Code using these experimental features must be updated.
  • Middleware Convention: A deprecated middleware convention is being replaced, requiring migration to a new proxy setup.
  • Stricter Environment Variables: Next.js 16 has stricter validation for environment variables, which may cause issues in existing setups.

Source: Next.js 16 Upgrade Guide

Recommendation: This is a high-effort migration. It is strongly recommended to run the official codemod (pnpm dlx @next/codemod@canary upgrade latest) in a separate branch to handle the initial updates. Thoroughly test the application afterward, paying close attention to middleware, environment variables, and any previously experimental features.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@vercel

vercel Bot commented Aug 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
genstore Error Error Aug 25, 2026 1:10am

@coderabbitai

coderabbitai Bot commented Aug 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 55c5bf95-c7ee-4b45-b151-791b233c8267

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9ca04a2864

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
"input-otp": "^1.4.2",
"lucide-react": "^0.525.0",
"next": "15.3.5",
"next": "16.3.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Commit the Bun lockfile update for this upgrade

This bumps package.json, but the committed bun.lock still records the workspace dependency as "next": "15.3.5" and the resolved package as next@15.3.5, including the old nested postcss version. Because this repo commits bun.lock, any install/build path that relies on the checked-in Bun lockfile or uses a frozen install (Bun help: --frozen-lockfile Disallow changes to lockfile) will either keep using the vulnerable Next version or fail instead of applying the intended security fix. Please regenerate and commit bun.lock with the Next 16.3.0 resolution.

Useful? React with 👍 / 👎.

This branch had an error being deployed

1 failed deployment
Preview 9ca04a28 Deployed Aug 25, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants