-
Notifications
You must be signed in to change notification settings - Fork 6.4k
Bump next from 15.5.9 to 16.1.5 #3990
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
Bumps [next](https://github.com/vercel/next.js) from 15.5.9 to 16.1.5. - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v15.5.9...v16.1.5) --- updated-dependencies: - dependency-name: next dependency-version: 16.1.5 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
3 Skipped Deployments
|
Greptile OverviewGreptile SummaryThis PR upgrades Next.js from version 15.5.9 to 16.1.5, a major version bump that includes critical security fixes and performance improvements. Key Changes:
Compatibility Assessment:
Potential Concerns:
Confidence Score: 4/5
Important Files Changed
Sequence DiagramsequenceDiagram
participant Dev as Developer
participant Dep as Dependabot
participant CI as CI/CD Pipeline
participant App as Umami App
participant Next as Next.js Runtime
Dep->>Dep: Detect Next.js security update
Dep->>Dev: Create PR #3990 (15.5.9→16.1.5)
Note over Dep,Dev: Includes CVE fixes for DoS vulnerabilities
Dev->>CI: Trigger build & tests
CI->>CI: Install dependencies (pnpm)
CI->>CI: Run build-app (next build --turbo)
CI->>Next: Initialize Next.js 16.1.5 with Turbopack
Next->>Next: Apply security patches (CVE fixes)
Next->>Next: Apply image optimization limits (50MB)
Next->>CI: Build complete
CI->>CI: Run test suite
CI->>Dev: Report build & test results
alt Tests Pass
Dev->>Dev: Review changes & test locally
Dev->>App: Merge & deploy
App->>Next: Runtime with security fixes active
Note over App,Next: Protected against DoS vulnerabilities
else Tests Fail
Dev->>Dev: Investigate breaking changes
Dev->>Dev: Fix compatibility issues
end
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
2 files reviewed, no comments
Bumps next from 15.5.9 to 16.1.5.
Release notes
Sourced from next's releases.
... (truncated)
Commits
acba4a6v16.1.5e1d1fc6Add maximum size limit for postponed body parsing (#88175)500ec83fetch(next/image): reduce maximumResponseBody from 300MB to 50MB (#88588)1caaca3feat(next/image)!: addimages.maximumResponseBodyconfig (#88183)522ed84Sync DoS mitigations for React Flight8cad197[backport][cna] Ensure created app is not considered the workspace root in pn...2718661Backport/docs fixes (#89031)5333625Backport/docs fixes 16.1.5 (#88916)60de6c2v16.1.45f75d22backport: Only filter next config if experimental flag is enabled (#88733) (#...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.