Skip to content

Commit 96b7733

Browse files
chore(deps): Bump next from 16.2.11 to 16.3.8 in /dev-packages/e2e-tests/test-applications/nextjs-16 (#25179)
Bumps [next](https://github.com/vercel/next.js) from 16.2.11 to 16.3.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vercel/next.js/releases">next's releases</a>.</em></p> <blockquote> <h2>v16.3.8</h2> <p>This release contains security fixes for the following advisories:</p> <p>High:</p> <ul> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-cjq9-62q9-8jv4">Server-Side Request Forgery in Image Optimization</a></li> </ul> <p>Medium:</p> <ul> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-f87g-xv8r-7p7x">Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass</a></li> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676">Cache poisoning of SSG and ISR pages in self-hosted Next.js applications</a></li> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-mcj8-r9mp-w47p">Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service</a></li> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-3w37-wq28-93x7">Pending <code>use cache</code> fill can leak Draft Mode content into regular responses and persisted pages</a></li> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-h694-7cp9-m8p3">Cache leak across root param values in nested 'use cache' functions</a></li> </ul> <p>Low:</p> <ul> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-39w2-rjm5-chcv">Information disclosure in the Next.js development server's Model Context Protocol endpoint</a></li> </ul> <h2>v16.3.7</h2> <blockquote> <p>[!NOTE] This release is backporting bug fixes. It does <strong>not</strong> include all pending features/changes on canary.</p> </blockquote> <h3>Core Changes</h3> <ul> <li>turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (<a href="https://redirect.github.com/vercel/next.js/issues/98931">#98931</a>)</li> </ul> <h3>Credits</h3> <p>Huge thanks to <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> for helping!</p> <h2>v16.3.6</h2> <p>This release contains a security fix for <a href="https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j">GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse</a></p> <h2>v16.3.5</h2> <p>The following bug fixes have been backported. It does not include all pending features/changes on canary.</p> <ul> <li>next/image: Skip 0-byte entries when initializing disk LRU cache (<a href="https://redirect.github.com/vercel/next.js/issues/98185">#98185</a>)</li> <li>next/image: Reject empty images when reading/writing to the disk cache (<a href="https://redirect.github.com/vercel/next.js/issues/98186">#98186</a>)</li> <li>Emit whole-app server NFTs when <code>output: 'standalone'</code> is used with an adapter (<a href="https://redirect.github.com/vercel/next.js/issues/98167">#98167</a>)</li> <li>Add CSP nonce to script tags of loading and template files (<a href="https://redirect.github.com/vercel/next.js/issues/98403">#98403</a>)</li> <li>Fix <code>use cache</code> prerender signal retention (<a href="https://redirect.github.com/vercel/next.js/issues/98448">#98448</a>)</li> </ul> <h2>v16.3.4</h2> <p>Follow-up release to <a href="https://github.com/vercel/next.js/releases/tag/v16.3.3">v16.3.3</a> re-enabling AVIF Image Optimization (<a href="https://redirect.github.com/vercel/next.js/pull/97949">#97949</a>).</p> <p>The following bug fixes have been backported. It does <strong>not</strong> include all pending features/changes on canary.</p> <ul> <li>testmode: Fix infinite recursion in testmode passthrough fetch (<a href="https://redirect.github.com/vercel/next.js/issues/97691">#97691</a>)</li> <li>Fix build error when aliasing typescript to <code>@​typescript/typescript6</code> (<a href="https://redirect.github.com/vercel/next.js/issues/97997">#97997</a>)</li> <li>Fix unset crossOrigin in Turbopack manifests (<a href="https://redirect.github.com/vercel/next.js/issues/97930">#97930</a>)</li> </ul> <h3>Credits</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vercel/next.js/commit/b0fad0d45eb4c4430fda5eeeb442e8a5af08a5f6"><code>b0fad0d</code></a> v16.3.8</li> <li><a href="https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"><code>719e4c6</code></a> [lts-active] Scope response cache keys to their source route (<a href="https://redirect.github.com/vercel/next.js/issues/218">#218</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/e92db4536a7f34ae2dbda583cfa1b4e0d06d1865"><code>e92db45</code></a> [lts-active] Fix metadata propagation for deduplicated nested caches (<a href="https://redirect.github.com/vercel/next.js/issues/223">#223</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/40c2ba904289a65ed2fd4633c5dfb1bdc29b52de"><code>40c2ba9</code></a> [lts-active] Match Next data paths case-sensitively (<a href="https://redirect.github.com/vercel/next.js/issues/196">#196</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476"><code>2d9f50a</code></a> [lts-active] Fix MCP middleware DNS rebinding (<a href="https://redirect.github.com/vercel/next.js/issues/213">#213</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/bd9214f9a32854a011bf5fe58e481dffe1bbf598"><code>bd9214f</code></a> [lts-active] Fix draft mode leaks through cross-request <code>'use cache'</code> dedupli...</li> <li><a href="https://github.com/vercel/next.js/commit/8db4a627c91e718514406ff5644ea4985dcaaae0"><code>8db4a62</code></a> [lts-active][webpack] Ensure <code>dynamicParams</code> is respected in `opengraph-image...</li> <li><a href="https://github.com/vercel/next.js/commit/e002ad68bd676bb0ed0c87bb22e3590304763e0b"><code>e002ad6</code></a> [lts-active] fix(next/image): Pin DNS resolution when fetching external image...</li> <li><a href="https://github.com/vercel/next.js/commit/4c20699e29178d444994cf5a31b8a617ca3a2c80"><code>4c20699</code></a> v16.3.7</li> <li><a href="https://github.com/vercel/next.js/commit/2521aec5815e7de2121db253d12dae9f13e25361"><code>2521aec</code></a> [backport] turbo-tasks-backend: fix strongly consistent read hanging on a can...</li> <li>Additional commits viewable in <a href="https://github.com/vercel/next.js/compare/v16.2.11...v16.3.8">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=next&package-manager=npm_and_yarn&previous-version=16.2.11&new-version=16.3.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent a3dfc27 commit 96b7733

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

  • dev-packages/e2e-tests/test-applications/nextjs-16

‎dev-packages/e2e-tests/test-applications/nextjs-16/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
"ai": "^3.0.0",
3737
"import-in-the-middle": "^2",
3838
"ioredis": "5.10.1",
39-
"next": "16.2.11",
39+
"next": "16.3.8",
4040
"openai": "5.18.1",
4141
"pg": "^8.13.1",
4242
"react": "19.1.0",

0 commit comments

Comments
 (0)