Skip to content

chore(deps): bump next and eslint-config-next to 16.2.6 - #51

Merged
yigitdot merged 2 commits into
mainfrom
chore/next-16.2.6
May 9, 2026
Merged

yigitdot merged 2 commits into
mainfrom
chore/next-16.2.6

Conversation

@yigitdot

@yigitdot yigitdot commented May 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Bumps next and eslint-config-next from 16.2.4 → 16.2.6, picking up the 2026-05-07 security release (12 advisories: 7 high, 4 moderate, 2 low — DoS in Server Components, middleware/proxy bypasses, RSC cache poisoning, XSS via CSP nonces, etc.).
  • The site is statically exported (output: "export"), so the runtime advisories don't execute against deployed assets — but this keeps the dev toolchain off a flagged version and clears Dependabot.
  • Declares engines.node: ">=20.9.0" in package.json to match next 16.2.6's stated minimum, so fresh clones surface the requirement instead of failing opaquely.
  • Lockfile regen also pruned a stale @formspree/react entry that was lingering in pnpm-lock.yaml but not in package.json.

Test plan

  • pnpm lint
  • pnpm build (static export under Next.js 16.2.6)
  • pnpm dev → curl http://localhost:3000/ returns HTTP 200 with the homepage <title> rendered

Patches 12 advisories from the 2026-05-07 Next.js security release
(7 high / 4 moderate / 2 low). Static-export build is unaffected at
runtime; the bump keeps the dev toolchain off a flagged version.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings May 9, 2026 04:15
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 9, 2026 •

Copy link
Copy Markdown

Deploying website with  Cloudflare Pages  Cloudflare Pages

Latest commit: 833e723
Status: ✅  Deploy successful!
Preview URL: https://78278477.website-70y.pages.dev
Branch Preview URL: https://chore-next-16-2-6.website-70y.pages.dev

View logs

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the project’s Next.js toolchain to pick up the 16.2.6 security release, keeping the marketing site’s dependency set off a flagged version while maintaining static-export behavior.

Changes:

  • Bump next from 16.2.4 → 16.2.6.
  • Bump eslint-config-next from 16.2.4 → 16.2.6.
  • Regenerate pnpm-lock.yaml to reflect updated transitive dependencies.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
package.json Pins next and eslint-config-next to 16.2.6.
pnpm-lock.yaml Updates lockfile entries for Next.js 16.2.6 and related transitive packages.
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread package.json
Comment on lines 26 to 29
"dependencies": {
"next": "16.2.4",
"next": "16.2.6",
"react": "19.2.4",
"react-dom": "19.2.4"

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call — folded into 833e723: engines.node set to >=20.9.0 to match next 16.2.6's declared requirement.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates next and eslint-config-next to version 16.2.6, along with their associated dependencies and lockfile entries. It also consolidates nanoid versions by updating postcss to use version 3.3.12 and removing the older 3.3.11 version. I have no feedback to provide.

next 16.2.6 requires Node >=20.9.0; surface that to contributors so
fresh clones get a clear hint instead of hitting a Next runtime error.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@yigitdot
yigitdot merged commit 4315e35 into main May 9, 2026
8 checks passed
@yigitdot
yigitdot deleted the chore/next-16.2.6 branch May 9, 2026 04:34
@yigitdot
yigitdot requested a review from thiras May 9, 2026 04:34
thiras added a commit that referenced this pull request May 11, 2026
Adds two top-level config files split out of #51:

- .nvmrc -> 24, matches the version CI runs in
  .github/workflows/website.yml and docs.yml. Picked up
  automatically by nvm/fnm/Volta so local Node tracks CI.
- .npmrc -> engine-strict=true, makes pnpm install hard-fail
  on engines.node mismatch instead of just warning. Turns the
  >=20.9.0 floor declared in package.json (from #51) into an
  enforced contract.

Closes #52.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants