Update dependencies for Next.js May 2026 security release - #31
Conversation
- next 16.1.1 -> 16.2.10, eslint-config-next 16.1.1 -> 16.2.10 (fixes DoS, middleware/proxy bypass, SSRF, cache poisoning and XSS advisories; patched line is >= 16.2.6) - react / react-dom ^19.2.3 -> ^19.2.6 (resolved 19.2.7) - refresh all in-range minor/patch dependencies via yarn upgrade
|
Note: Next.js 16.2.x dev mode (Turbopack) has an upstream regression where Radix |
- poweredByHeader: false removes the X-Powered-By: Next.js header
- a postbuild script blanks the version embedded by the client runtime
(window.next={version:"..."}), which tools like Wappalyzer read; the
replacement is length-padded so source maps stay position-accurate.
Next.js offers no config for this (vercel/next.js#72471)
|
Added a follow-up commit that hides the Next.js version from browser fingerprinting: |
The scripts/ directory holds Node build scripts (CommonJS); the shared react-hooks rule block applies to every file, but the plugin-providing Next.js configs do not match .cjs, so ESLint fails to resolve the rule there.
The header only names the framework and never includes a version, so poweredByHeader: false is unnecessary for version-disclosure purposes. The postbuild strip of window.next.version is what hides the version.
Remove scripts/strip-next-version.cjs, its postbuild hook and the scripts/ ESLint ignore; hiding the framework version is not worth maintaining a custom build step.
|
The version-hiding postbuild tooling has been dropped from this PR (not worth maintaining a custom build step). The PR is back to a pure dependency update. |
Summary
Dependency updates addressing the Next.js May 2026 security release (13 advisories: DoS, middleware/proxy bypass, SSRF, cache poisoning, XSS). The patched line for Next.js 16.x is >= 16.2.6.
next16.1.1 → 16.2.10,eslint-config-next16.1.1 → 16.2.10react/react-dom^19.2.3 → ^19.2.6 (resolves 19.2.7)yarn upgrade(Storybook 10.4.6, tailwindcss 4.3.2, radix-ui 1.6.2, prettier 3.9.4, axios 1.18.1, recharts 3.9.2, etc.)No source code changes.
Verification
yarn lint(ESLint + Prettier check) ✅yarn typecheck✅yarn build✅