Repository navigation
Commit 96b7733
authored
chore(deps): Bump next from 16.2.11 to 16.3.8 in /dev-packages/e2e-tests/test-applications/nextjs-16 (#25179)
Bumps [next](https://github.com/vercel/next.js) from 16.2.11 to 16.3.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/next.js/releases">next's
releases</a>.</em></p>
<blockquote>
<h2>v16.3.8</h2>
<p>This release contains security fixes for the following
advisories:</p>
<p>High:</p>
<ul>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-cjq9-62q9-8jv4">Server-Side
Request Forgery in Image Optimization</a></li>
</ul>
<p>Medium:</p>
<ul>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-f87g-xv8r-7p7x">Information
disclosure in Next.js App Router metadata image routes via dynamicParams
bypass</a></li>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676">Cache
poisoning of SSG and ISR pages in self-hosted Next.js
applications</a></li>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-mcj8-r9mp-w47p">Cache
poisoning in Next.js SSG/ISR rendering leads to cross-user content
substitution and persistent denial of service</a></li>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-3w37-wq28-93x7">Pending
<code>use cache</code> fill can leak Draft Mode content into regular
responses and persisted pages</a></li>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-h694-7cp9-m8p3">Cache
leak across root param values in nested 'use cache' functions</a></li>
</ul>
<p>Low:</p>
<ul>
<li><a
href="https://github.com/vercel/next.js/security/advisories/GHSA-39w2-rjm5-chcv">Information
disclosure in the Next.js development server's Model Context Protocol
endpoint</a></li>
</ul>
<h2>v16.3.7</h2>
<blockquote>
<p>[!NOTE]
This release is backporting bug fixes. It does <strong>not</strong>
include all pending features/changes on canary.</p>
</blockquote>
<h3>Core Changes</h3>
<ul>
<li>turbo-tasks-backend: fix strongly consistent read hanging on a
canceled task (<a
href="https://redirect.github.com/vercel/next.js/issues/98931">#98931</a>)</li>
</ul>
<h3>Credits</h3>
<p>Huge thanks to <a
href="https://github.com/lukesandberg"><code>@lukesandberg</code></a>
for helping!</p>
<h2>v16.3.6</h2>
<p>This release contains a security fix for <a
href="https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j">GHSA-vcvr-r3jv-pc5j:
Remote Code Execution in next/og ImageResponse</a></p>
<h2>v16.3.5</h2>
<p>The following bug fixes have been backported. It does not include all
pending features/changes on canary.</p>
<ul>
<li>next/image: Skip 0-byte entries when initializing disk LRU cache (<a
href="https://redirect.github.com/vercel/next.js/issues/98185">#98185</a>)</li>
<li>next/image: Reject empty images when reading/writing to the disk
cache (<a
href="https://redirect.github.com/vercel/next.js/issues/98186">#98186</a>)</li>
<li>Emit whole-app server NFTs when <code>output: 'standalone'</code> is
used with an adapter (<a
href="https://redirect.github.com/vercel/next.js/issues/98167">#98167</a>)</li>
<li>Add CSP nonce to script tags of loading and template files (<a
href="https://redirect.github.com/vercel/next.js/issues/98403">#98403</a>)</li>
<li>Fix <code>use cache</code> prerender signal retention (<a
href="https://redirect.github.com/vercel/next.js/issues/98448">#98448</a>)</li>
</ul>
<h2>v16.3.4</h2>
<p>Follow-up release to <a
href="https://github.com/vercel/next.js/releases/tag/v16.3.3">v16.3.3</a>
re-enabling AVIF Image Optimization (<a
href="https://redirect.github.com/vercel/next.js/pull/97949">#97949</a>).</p>
<p>The following bug fixes have been backported. It does
<strong>not</strong> include all pending features/changes on canary.</p>
<ul>
<li>testmode: Fix infinite recursion in testmode passthrough fetch (<a
href="https://redirect.github.com/vercel/next.js/issues/97691">#97691</a>)</li>
<li>Fix build error when aliasing typescript to
<code>@typescript/typescript6</code> (<a
href="https://redirect.github.com/vercel/next.js/issues/97997">#97997</a>)</li>
<li>Fix unset crossOrigin in Turbopack manifests (<a
href="https://redirect.github.com/vercel/next.js/issues/97930">#97930</a>)</li>
</ul>
<h3>Credits</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/next.js/commit/b0fad0d45eb4c4430fda5eeeb442e8a5af08a5f6"><code>b0fad0d</code></a>
v16.3.8</li>
<li><a
href="https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"><code>719e4c6</code></a>
[lts-active] Scope response cache keys to their source route (<a
href="https://redirect.github.com/vercel/next.js/issues/218">#218</a>)</li>
<li><a
href="https://github.com/vercel/next.js/commit/e92db4536a7f34ae2dbda583cfa1b4e0d06d1865"><code>e92db45</code></a>
[lts-active] Fix metadata propagation for deduplicated nested caches (<a
href="https://redirect.github.com/vercel/next.js/issues/223">#223</a>)</li>
<li><a
href="https://github.com/vercel/next.js/commit/40c2ba904289a65ed2fd4633c5dfb1bdc29b52de"><code>40c2ba9</code></a>
[lts-active] Match Next data paths case-sensitively (<a
href="https://redirect.github.com/vercel/next.js/issues/196">#196</a>)</li>
<li><a
href="https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476"><code>2d9f50a</code></a>
[lts-active] Fix MCP middleware DNS rebinding (<a
href="https://redirect.github.com/vercel/next.js/issues/213">#213</a>)</li>
<li><a
href="https://github.com/vercel/next.js/commit/bd9214f9a32854a011bf5fe58e481dffe1bbf598"><code>bd9214f</code></a>
[lts-active] Fix draft mode leaks through cross-request <code>'use
cache'</code> dedupli...</li>
<li><a
href="https://github.com/vercel/next.js/commit/8db4a627c91e718514406ff5644ea4985dcaaae0"><code>8db4a62</code></a>
[lts-active][webpack] Ensure <code>dynamicParams</code> is respected in
`opengraph-image...</li>
<li><a
href="https://github.com/vercel/next.js/commit/e002ad68bd676bb0ed0c87bb22e3590304763e0b"><code>e002ad6</code></a>
[lts-active] fix(next/image): Pin DNS resolution when fetching external
image...</li>
<li><a
href="https://github.com/vercel/next.js/commit/4c20699e29178d444994cf5a31b8a617ca3a2c80"><code>4c20699</code></a>
v16.3.7</li>
<li><a
href="https://github.com/vercel/next.js/commit/2521aec5815e7de2121db253d12dae9f13e25361"><code>2521aec</code></a>
[backport] turbo-tasks-backend: fix strongly consistent read hanging on
a can...</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/next.js/compare/v16.2.11...v16.3.8">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/getsentry/sentry-javascript/network/alerts).
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent a3dfc27 commit 96b7733
1 file changed
Lines changed: 1 addition & 1 deletion
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| |||
0 commit comments