chore(deps): bump next and eslint-config-next to 16.2.6 - #51
Conversation
Patches 12 advisories from the 2026-05-07 Next.js security release (7 high / 4 moderate / 2 low). Static-export build is unaffected at runtime; the bump keeps the dev toolchain off a flagged version. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Deploying website with
|
| Latest commit: |
833e723
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://78278477.website-70y.pages.dev |
| Branch Preview URL: | https://chore-next-16-2-6.website-70y.pages.dev |
There was a problem hiding this comment.
Pull request overview
Updates the project’s Next.js toolchain to pick up the 16.2.6 security release, keeping the marketing site’s dependency set off a flagged version while maintaining static-export behavior.
Changes:
- Bump
nextfrom16.2.4→16.2.6. - Bump
eslint-config-nextfrom16.2.4→16.2.6. - Regenerate
pnpm-lock.yamlto reflect updated transitive dependencies.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| package.json | Pins next and eslint-config-next to 16.2.6. |
| pnpm-lock.yaml | Updates lockfile entries for Next.js 16.2.6 and related transitive packages. |
Files not reviewed (1)
- pnpm-lock.yaml: Language not supported
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| "dependencies": { | ||
| "next": "16.2.4", | ||
| "next": "16.2.6", | ||
| "react": "19.2.4", | ||
| "react-dom": "19.2.4" |
There was a problem hiding this comment.
Good call — folded into 833e723: engines.node set to >=20.9.0 to match next 16.2.6's declared requirement.
There was a problem hiding this comment.
Code Review
This pull request updates next and eslint-config-next to version 16.2.6, along with their associated dependencies and lockfile entries. It also consolidates nanoid versions by updating postcss to use version 3.3.12 and removing the older 3.3.11 version. I have no feedback to provide.
next 16.2.6 requires Node >=20.9.0; surface that to contributors so fresh clones get a clear hint instead of hitting a Next runtime error. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds two top-level config files split out of #51: - .nvmrc -> 24, matches the version CI runs in .github/workflows/website.yml and docs.yml. Picked up automatically by nvm/fnm/Volta so local Node tracks CI. - .npmrc -> engine-strict=true, makes pnpm install hard-fail on engines.node mismatch instead of just warning. Turns the >=20.9.0 floor declared in package.json (from #51) into an enforced contract. Closes #52.
Summary
nextandeslint-config-nextfrom16.2.4→16.2.6, picking up the 2026-05-07 security release (12 advisories: 7 high, 4 moderate, 2 low — DoS in Server Components, middleware/proxy bypasses, RSC cache poisoning, XSS via CSP nonces, etc.).output: "export"), so the runtime advisories don't execute against deployed assets — but this keeps the dev toolchain off a flagged version and clears Dependabot.engines.node: ">=20.9.0"inpackage.jsonto match next 16.2.6's stated minimum, so fresh clones surface the requirement instead of failing opaquely.@formspree/reactentry that was lingering inpnpm-lock.yamlbut not inpackage.json.Test plan
pnpm lintpnpm build(static export under Next.js 16.2.6)pnpm dev→curl http://localhost:3000/returns HTTP 200 with the homepage<title>rendered