Bump next from 16.3.0 to 16.3.3 #29

Open
dependabot[bot] wants to merge 1 commits from dependabot/npm_and_yarn/next-16.3.3 into main
dependabot[bot] commented 2026-09-11 06:57:41 +02:00 (Migrated from github.com)

Bumps next from 16.3.0 to 16.3.3.

Release notes

Sourced from next's releases.

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

v16.3.1

What's Changed

Full Changelog: https://github.com/vercel/next.js/compare/v16.3.0...v16.3.1

... (truncated)

Commits
  • a9a1cb7 v16.3.3
  • 968b9fc [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows
  • 3a15b4a [16.3.x] [next/image]: disable avif image optimization
  • 7378b51 Backport/docs fixes 16.3 (#97649)
  • 528c1cd [16.3.x] Stop generating error codes (#97780)
  • d0ac882 v16.3.2
  • 81deb92 [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...
  • cd714d9 [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • 5ac2327 [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • 0ccb3e7 [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.
Bumps [next](https://github.com/vercel/next.js) from 16.3.0 to 16.3.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vercel/next.js/releases">next's releases</a>.</em></p> <blockquote> <h2>v16.3.3</h2> <p>This release contains security fixes for the following advisories:</p> <p>Critical:</p> <ul> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36">Unauthenticated Remote Code Execution on windows-hosted servers</a></li> <li><a href="https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4">Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used</a></li> </ul> <h2>v16.3.2</h2> <blockquote> <p>[!NOTE] This release is backporting bug fixes. It does <strong>not</strong> include all pending features/changes on canary.</p> </blockquote> <h3>Core Changes</h3> <ul> <li>[backport] Scope app-entry export validation to files inside the app directory (<a href="https://redirect.github.com/vercel/next.js/issues/97357">#97357</a>)</li> <li>[backport] Fix catch-all index page being served for every other slug (<a href="https://redirect.github.com/vercel/next.js/issues/97416">#97416</a>)</li> <li>[16.3] Turbopack: don't trace embedded WASM loader helpers (<a href="https://redirect.github.com/vercel/next.js/issues/97353">#97353</a>) (<a href="https://redirect.github.com/vercel/next.js/issues/97463">#97463</a>)</li> <li>[16.3] Turbopack: retain conditions when replacing resolve request keys (<a href="https://redirect.github.com/vercel/next.js/issues/97453">#97453</a>)</li> <li>[16.3.x] Fix Turbopack worker chunk loading with asset prefix (<a href="https://redirect.github.com/vercel/next.js/issues/97419">#97419</a>)</li> <li>[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (<a href="https://redirect.github.com/vercel/next.js/issues/97603">#97603</a>)</li> </ul> <h3>Credits</h3> <p>Huge thanks to <a href="https://github.com/lubieowoce"><code>@​lubieowoce</code></a>, <a href="https://github.com/unstubbable"><code>@​unstubbable</code></a>, <a href="https://github.com/timneutkens"><code>@​timneutkens</code></a>, <a href="https://github.com/mischnic"><code>@​mischnic</code></a>, and <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> for helping!</p> <h2>v16.3.1</h2> <h2>What's Changed</h2> <ul> <li>[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/96653">vercel/next.js#96653</a></li> <li>[16.x] [turbopack] Add <code>turbopack_ecmascript</code> and <code>turbopack_wasm</code>'s embeded FS to <code>internal_assets_conditions</code> by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/96655">vercel/next.js#96655</a></li> <li>[16.x] [turbopack] Collapse nested promises in the analyzer by <a href="https://github.com/sampoder"><code>@​sampoder</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/96675">vercel/next.js#96675</a></li> <li>[16.x] fix(next/image): preserve image response after optimization by <a href="https://github.com/styfle"><code>@​styfle</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/96733">vercel/next.js#96733</a></li> <li>[16.3.x] Default deploy e2e tests to the repo next version by <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/96900">vercel/next.js#96900</a></li> <li>[backport] Bump <code>@​swc/helpers</code> by <a href="https://github.com/mischnic"><code>@​mischnic</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/96885">vercel/next.js#96885</a></li> <li>[backport] [turbopack] Raise registration calls in hoisted modules to the top by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97308">vercel/next.js#97308</a></li> <li>[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97302">vercel/next.js#97302</a></li> <li>[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97317">vercel/next.js#97317</a></li> <li>[backport] Restore the live <code>headers()</code> view of the incoming request by <a href="https://github.com/unstubbable"><code>@​unstubbable</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97311">vercel/next.js#97311</a></li> <li>[backport] Allow literal exports in <code>'use cache'</code> files by <a href="https://github.com/unstubbable"><code>@​unstubbable</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97312">vercel/next.js#97312</a></li> <li>[backport] Keep the dev validation worker alive across HMR updates by <a href="https://github.com/unstubbable"><code>@​unstubbable</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97315">vercel/next.js#97315</a></li> <li>[backport] Discard only cache entries that predate a tag revalidation, and reuse completed entries by <a href="https://github.com/unstubbable"><code>@​unstubbable</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97314">vercel/next.js#97314</a></li> <li>[backport] Encode the cache item name built by <code>unstable_cache</code> by <a href="https://github.com/unstubbable"><code>@​unstubbable</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97313">vercel/next.js#97313</a></li> <li>[16.3] [ci] Use OIDC tokens to read private preview builds by <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97258">vercel/next.js#97258</a></li> <li>[backport] [test] Compile the middleware redirect routes up front in dev by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97328">vercel/next.js#97328</a></li> <li>[backport] Fix Nav Inspector request loop on repeat captures by <a href="https://github.com/acdlite"><code>@​acdlite</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97326">vercel/next.js#97326</a></li> <li>[backport] Fix: Optimistic routing bugs leading to repeated prefetch loops by <a href="https://github.com/acdlite"><code>@​acdlite</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97325">vercel/next.js#97325</a></li> <li>[backport] Retain fewer stale cache versions and use a TTL, plus the mtime fallback by <a href="https://github.com/lukesandberg"><code>@​lukesandberg</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97304">vercel/next.js#97304</a></li> <li>[backport] Revert i18n localization change for dynamic Pages API routes (<a href="https://redirect.github.com/vercel/next.js/issues/94905">#94905</a>) by <a href="https://github.com/gaojude"><code>@​gaojude</code></a> in <a href="https://redirect.github.com/vercel/next.js/pull/97330">vercel/next.js#97330</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/vercel/next.js/compare/v16.3.0...v16.3.1">https://github.com/vercel/next.js/compare/v16.3.0...v16.3.1</a></p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586"><code>a9a1cb7</code></a> v16.3.3</li> <li><a href="https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b"><code>968b9fc</code></a> [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows</li> <li><a href="https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3"><code>3a15b4a</code></a> [16.3.x] [next/image]: disable avif image optimization</li> <li><a href="https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16"><code>7378b51</code></a> Backport/docs fixes 16.3 (<a href="https://redirect.github.com/vercel/next.js/issues/97649">#97649</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/528c1cdfc36bdf8051992febdafe45f17f042010"><code>528c1cd</code></a> [16.3.x] Stop generating error codes (<a href="https://redirect.github.com/vercel/next.js/issues/97780">#97780</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/d0ac8828c2fe6026dd7d700488bfd8289711fde6"><code>d0ac882</code></a> v16.3.2</li> <li><a href="https://github.com/vercel/next.js/commit/81deb92859e26f8435cc0f37e244573c6638a955"><code>81deb92</code></a> [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...</li> <li><a href="https://github.com/vercel/next.js/commit/cd714d9fceae7aec9d467598792b0c844f710607"><code>cd714d9</code></a> [16.3.x] Fix Turbopack worker chunk loading with asset prefix (<a href="https://redirect.github.com/vercel/next.js/issues/97419">#97419</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/5ac2327e62784eacdf6ab7db8629fd05c5f5fcdf"><code>5ac2327</code></a> [16.3] Turbopack: retain conditions when replacing resolve request keys (<a href="https://redirect.github.com/vercel/next.js/issues/97453">#97453</a>)</li> <li><a href="https://github.com/vercel/next.js/commit/0ccb3e7f5d6b55c5c9e215248b264a428aee7dcb"><code>0ccb3e7</code></a> [16.3] Turbopack: don't trace embedded WASM loader helpers (<a href="https://redirect.github.com/vercel/next.js/issues/97353">#97353</a>) (<a href="https://redirect.github.com/vercel/next.js/issues/97463">#97463</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vercel/next.js/compare/v16.3.0...v16.3.3">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=next&package-manager=npm_and_yarn&previous-version=16.3.0&new-version=16.3.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Quinta0/valgo/network/alerts). </details>
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin dependabot/npm_and_yarn/next-16.3.3:dependabot/npm_and_yarn/next-16.3.3
git checkout dependabot/npm_and_yarn/next-16.3.3
Sign in to join this conversation.