Skip to content

Update dependencies for Next.js May 2026 security release - #31

Merged
fyui001 merged 5 commits into
NewWorldOrg:masterfrom
fyui001:chore/next-security-update-may-2026
Jul 8, 2026
Merged

fyui001 merged 5 commits into
NewWorldOrg:masterfrom
fyui001:chore/next-security-update-may-2026

Conversation

@fyui001

@fyui001 fyui001 commented Jul 8, 2026

Copy link
Copy Markdown
Member

Summary

Dependency updates addressing the Next.js May 2026 security release (13 advisories: DoS, middleware/proxy bypass, SSRF, cache poisoning, XSS). The patched line for Next.js 16.x is >= 16.2.6.

  • next 16.1.1 → 16.2.10, eslint-config-next 16.1.1 → 16.2.10
  • react / react-dom ^19.2.3 → ^19.2.6 (resolves 19.2.7)
  • All other in-range minor/patch dependencies refreshed via yarn upgrade (Storybook 10.4.6, tailwindcss 4.3.2, radix-ui 1.6.2, prettier 3.9.4, axios 1.18.1, recharts 3.9.2, etc.)

No source code changes.

Verification

  • yarn lint (ESLint + Prettier check) ✅
  • yarn typecheck ✅
  • yarn build ✅
  • Visual smoke check of the running app (login page renders correctly) ✅

- next 16.1.1 -> 16.2.10, eslint-config-next 16.1.1 -> 16.2.10
  (fixes DoS, middleware/proxy bypass, SSRF, cache poisoning and XSS
  advisories; patched line is >= 16.2.6)
- react / react-dom ^19.2.3 -> ^19.2.6 (resolved 19.2.7)
- refresh all in-range minor/patch dependencies via yarn upgrade
@fyui001 fyui001 self-assigned this Jul 8, 2026
@fyui001

fyui001 commented Jul 8, 2026

Copy link
Copy Markdown
Member Author

Note: Next.js 16.2.x dev mode (Turbopack) has an upstream regression where Radix SelectValue text portals render empty on next dev (bisected against next 16.2.6–16.2.10; radix-ui and react versions ruled out). Production builds (next build && next start) are unaffected. Select triggers with a selected value may appear blank on the dev server until Next.js ships a fix.

- poweredByHeader: false removes the X-Powered-By: Next.js header
- a postbuild script blanks the version embedded by the client runtime
  (window.next={version:"..."}), which tools like Wappalyzer read; the
  replacement is length-padded so source maps stay position-accurate.
  Next.js offers no config for this (vercel/next.js#72471)
@fyui001

fyui001 commented Jul 8, 2026

Copy link
Copy Markdown
Member Author

Added a follow-up commit that hides the Next.js version from browser fingerprinting: poweredByHeader: false (removes X-Powered-By) plus a postbuild script that blanks the window.next.version string embedded in the served client chunk (read by Wappalyzer and similar tools; no official Next.js config exists — vercel/next.js#72471). Verified on a production build: x-powered-by header gone, window.next.version === "", and no version string left in .next/static/chunks.

fyui001 added 3 commits July 8, 2026 12:28
The scripts/ directory holds Node build scripts (CommonJS); the shared
react-hooks rule block applies to every file, but the plugin-providing
Next.js configs do not match .cjs, so ESLint fails to resolve the rule
there.
The header only names the framework and never includes a version, so
poweredByHeader: false is unnecessary for version-disclosure purposes.
The postbuild strip of window.next.version is what hides the version.
Remove scripts/strip-next-version.cjs, its postbuild hook and the
scripts/ ESLint ignore; hiding the framework version is not worth
maintaining a custom build step.
@fyui001

fyui001 commented Jul 8, 2026

Copy link
Copy Markdown
Member Author

The version-hiding postbuild tooling has been dropped from this PR (not worth maintaining a custom build step). The PR is back to a pure dependency update.

@fyui001
fyui001 merged commit d04d918 into NewWorldOrg:master Jul 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant