Skip to content

Move the web app to Next 16 and pin the transitive deps that lagged - #6

Merged
lgoyal6 merged 1 commit into
mainfrom
web/next-16-and-transitive-pins
Sep 6, 2026
Merged

lgoyal6 merged 1 commit into
mainfrom
web/next-16-and-transitive-pins

Conversation

@lgoyal6

@lgoyal6 lgoyal6 commented Sep 6, 2026

Copy link
Copy Markdown
Collaborator

Why now

The frontend was on next 15.0.3 with a lockfile that had not been regenerated since. Two transitive packages were the reason to move rather than sit:

package was now direct dependency?
nanoid 3.3.14 3.3.18 no
sharp 0.33.5 0.35.4 no
next 15.0.3 16.3.4 yes
postcss 8.4.49 8.5.18 yes (dev)

Neither nanoid nor sharp is a direct dependency, so neither could be raised by editing the dependency list. An overrides block forces them through the whole tree, because overrides is the only lever npm gives you for a version you do not depend on directly.

tsconfig

tsconfig.json carries the changes Next 16 writes for itself on first run: jsx moves from "preserve" to "react-jsx", and .next/dev/types is added to include so the dev server's generated route types resolve. The reformatting to one entry per line is the same tool's doing, not a setting change.

How the upgrade is checked

The attest workflow that landed in #2 runs npm ci from this lockfile and then next build on every push. So the Next 16 build is exercised against exactly these bytes on this branch, rather than against whatever a local node_modules happened to hold. The green check on this PR is that build.

Tests

No Python changed, so the Python suite is reported for completeness only. .agent-work/ is excluded from discovery: worktrees under it hold duplicate copies of these same test files.

file result
test_token_merge.py 14/14
test_model_guard.py 21/21
attentionrag/test_core.py 10/10
experiments/test_data.py rc=0, 0 tests (fixture module)
total 45 passing, 0 failing

🤖 Generated with Claude Code

The frontend was on next 15.0.3 with a lockfile that had not been
regenerated since. Two transitive packages were the reason to move rather
than sit: nanoid resolved to 3.3.14 and sharp to 0.33.5, both below the
versions their maintainers now ship, and neither is a direct dependency
so neither could be raised by editing the dependency list.

  * next 15.0.3 -> ^16.3.4, postcss ^8.4.49 -> ^8.5.18
  * an "overrides" block forces nanoid ^3.3.18 and sharp ^0.35.0 through
    the whole tree, because overrides is the only lever npm gives you for
    a version you do not depend on directly
  * package-lock.json regenerated: nanoid 3.3.14 -> 3.3.18,
    sharp 0.33.5 -> 0.35.4, next 15.0.3 -> 16.3.4

tsconfig.json carries the changes Next 16 writes for itself on first run:
jsx moves from "preserve" to "react-jsx", and .next/dev/types is added to
include so the dev server's generated route types resolve. The
reformatting to one entry per line is the same tool's doing and is not a
setting change.

The attest workflow runs npm ci from this lockfile and then next build on
every push, so the build is checked against exactly these bytes rather
than against whatever a local node_modules happened to hold.
@lgoyal6
lgoyal6 merged commit 20a9cde into main Sep 6, 2026
1 check passed
@lgoyal6
lgoyal6 deleted the web/next-16-and-transitive-pins branch September 6, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant