Skip to content

chore(deps): bump next from 16.2.9 to 16.2.11 in /frontend - #44

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/next-16.2.11
Closed

chore(deps): bump next from 16.2.9 to 16.2.11 in /frontend#44
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/next-16.2.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor

Bumps next from 16.2.9 to 16.2.11.

Release notes

Sourced from next's releases.

v16.2.11

This release contains security fixes for the following advisories:

High:

Moderate:

v16.2.10

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 16.2.4.

Commits
  • 9beca08 v16.2.11
  • 3c48c7a [16.x] Fix Turbopack middleware matcher with i18n single locale
  • ac1eff3 [16.x] Improve performance of checking valid MPA form submissions
  • 9a4651e [16.x] Enforce serverActions.bodySizeLimit for Server Actions in Edge runtime
  • b512063 [16.x] Set correct origin for internal redirects in custom server
  • d303326 [16.x] Ensure exotic rewrite param values are properly encoded
  • 73b9487 [16.x] fix(fetch-cache): key fetch(Request, init) by the effective request
  • bf9d17f [16.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies
  • fe28768 [16.x] fix(next/image): improve performance of detectContentType()
  • d8afb8d [16.x] Performance improvements when decoding React Server function payloads
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 26, 2026
Bumps [next](https://github.com/vercel/next.js) from 16.2.9 to 16.2.11.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.9...v16.2.11)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.2.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/next-16.2.11 branch from 4ce74f7 to a4636a3 Compare July 26, 2026 18:41
timothybrown added a commit that referenced this pull request Jul 26, 2026
….7.26.2

Closes the second advisory wave that surfaced after v2026.7.26.1:

- next 16.2.9 -> 16.2.11 (batch of 18 Next.js advisories, 8 high / 10 medium,
  runtime). Supersedes Dependabot PR #44.
- js-yaml override 4.2.0 -> 4.3.0 (dev; advisory < 4.3.0)
- postcss override 8.5.15 -> 8.5.18 (build; advisory <= 8.5.17)

js-yaml and postcss are transitive deps pinned via pnpm.overrides, so
Dependabot's own security-update jobs for them fail with
security_update_not_possible — they can only be resolved by bumping the
overrides here.

next 16.2.11 shipped 2026-07-21 (5 days ago), inside the 7-day
minimum-release-age in .npmrc. Cooldown was bypassed for this one lockfile
regen only (npm_config_minimum_release_age=0); the committed .npmrc stays at
10080 and the lockfile churn is scoped strictly to next/js-yaml/postcss.
Verified: tsc clean, next build clean, 555 frontend tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QHDmg41wKKcwPreaoQyiGM
@dependabot @github

dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor Author

Looks like next is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 26, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/next-16.2.11 branch July 26, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants