Bump next from 13.5.4 to 16.2.6 in /client#120
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Holding this for a dedicated migration session — Next 13 → 16 is three major versions of breaking changes (14: Node minimum bump and App Router stabilization; 15: This also ideally lands together with the React 18 → 19 bump since Next 16 targets React 19, and #118 (React 18.2 → 18.3.1) is the safe stepping-stone for that. Worth noting that the release notes list a stack of unpatched advisories that affect 13.5.4 (middleware/proxy bypass, SSRF via WebSocket upgrades, multiple DoS vectors). Whenever this is sequenced, prioritize it over feature work — the CVE pile grows as the version drifts further from current. Leaving this Dependabot PR open as the reminder; will land via a dedicated branch when scheduled. |
Bumps [next](https://github.com/vercel/next.js) from 13.5.4 to 16.2.6. - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v13.5.4...v16.2.6) --- updated-dependencies: - dependency-name: next dependency-version: 16.2.6 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
387f9e1 to
71e4fce
Compare
Bumps next from 13.5.4 to 16.2.6.
Release notes
Sourced from next's releases.
... (truncated)
Commits
ee6e79bv16.2.6afa053dTurbopack: Match proxy matchers with webpack implementation (#93594)97a154eTurbopack: Fix middleware matcher suffix (#93590)83899bc[backport] Disable build caches for production/staging/force-preview deploys ...7b222b9[backport][test] Pin package manager to patch versions (#93595)a8dc24f[backport] Turbopack: more strict vergen setup (#93587)766148fv16.2.50dd9483fix: add explicit checks for RSC header (#83) (#98)d166096fix proxy matching for segment prefetch URLs (#89) (#96)9d50c0bStrip next-resume header from incoming requests (#92)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.