Skip to content

fix(deps): bump next from 16.3.6 to 16.3.8 - #914

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/next-16.3.8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/next-16.3.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps next from 16.3.6 to 16.3.8.

Release notes

Sourced from next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

Commits
  • b0fad0d v16.3.8
  • 719e4c6 [lts-active] Scope response cache keys to their source route (#218)
  • e92db45 [lts-active] Fix metadata propagation for deduplicated nested caches (#223)
  • 40c2ba9 [lts-active] Match Next data paths case-sensitively (#196)
  • 2d9f50a [lts-active] Fix MCP middleware DNS rebinding (#213)
  • bd9214f [lts-active] Fix draft mode leaks through cross-request 'use cache' dedupli...
  • 8db4a62 [lts-active][webpack] Ensure dynamicParams is respected in `opengraph-image...
  • e002ad6 [lts-active] fix(next/image): Pin DNS resolution when fetching external image...
  • 4c20699 v16.3.7
  • 2521aec [backport] turbo-tasks-backend: fix strongly consistent read hanging on a can...
  • See full diff in compare view


📝 Summary by GitNexus

Summary

A dependency-version update appears confined to package metadata and the lockfile, with no graph-traced downstream reach.

🟡 MEDIUM blast radius. This updates next from 16.3.6 to 16.3.8 in package.json and pnpm-lock.yaml, with no graph-traced dependents.

Review the declared dependency change alongside the resolved entries in pnpm-lock.yaml. The graph reports no affected execution flows, and there are no HIGH or CRITICAL risk files.

Added by GitNexus for PR #914. Edit freely — this block is replaced on the next review, everything above it is left untouched.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-knowledge-studio Error Error Oct 7, 2026 6:42am UTC

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nexus-check

nexus-check Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
Akon Labs

GitNexus Review · PR #914

No issues found in 2 changed files.

Summary

A dependency-version update appears confined to package metadata and the lockfile, with no graph-traced downstream reach.

🟡 MEDIUM blast radius. This updates next from 16.3.6 to 16.3.8 in package.json and pnpm-lock.yaml, with no graph-traced dependents.

Review the declared dependency change alongside the resolved entries in pnpm-lock.yaml. The graph reports no affected execution flows, and there are no HIGH or CRITICAL risk files.

Full detail lives in the GitNexus check run for this commit.

@nexus-check

nexus-check Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 Agent context for GitNexus Review · PR #914

This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.

🟡 MEDIUM blast radius — no downstream dependents were found in the code graph; a spot-check of the dependents should cover it. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)

Blast Level Dependents Modules Files
🟡 MEDIUM 0 0 2

What changed

Changed Files (2)
File Status
package.json 🟡 modified
pnpm-lock.yaml 🟡 modified

What to check

File Risk (2)
File Risk Category
package.json 🟡 MEDIUM Dependencies
pnpm-lock.yaml 🟢 LOW Lock File

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.3.8 branch from bfdf6ec to 8233077 Compare October 6, 2026 06:09
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.3.8 branch 2 times, most recently from dab112d to e18bfcd Compare October 6, 2026 13:47
Bumps [next](https://github.com/vercel/next.js) from 16.3.6 to 16.3.8.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.6...v16.3.8)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.3.8 branch from e18bfcd to ec2c85c Compare October 7, 2026 06:40
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Blocked merge diagnosis — blocked
⏳ Check run(s) still in progress: ["GitHub Actions Workflow Validation","YAML Syntax Validation","Detect Changes","Diagnose Blocked Merge State","Shell Script Security Analysis","Dependency Advisory Audit","Infrastructure as Code Security","Trivy Filesystem Security Scan","commitlint","Secret Detection","labeler","Codacy Static Code Analysis","GitNexus"]

This branch had an error being deployed

1 failed deployment
Preview — ec2c85cc Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants