Skip to content

chore(deps): bump next to 16.2.6#49

Open
charlesrhoward wants to merge 1 commit into
mainfrom
chore/next-16-2-6
Open

chore(deps): bump next to 16.2.6#49
charlesrhoward wants to merge 1 commit into
mainfrom
chore/next-16-2-6

Conversation

@charlesrhoward
Copy link
Copy Markdown
Contributor

@charlesrhoward charlesrhoward commented May 15, 2026

Summary

Patches the May 2026 Next.js security release. Affected: <= 16.2.5 on the 16.x line.

Release notes: https://vercel.com/changelog/next-js-may-2026-security-release

Files touched

  • package.jsonnext 16.2.3 → 16.2.6
  • pnpm-lock.yaml — regenerated

Test plan

  • pnpm install
  • pnpm build

🤖 Generated with Claude Code


View in Codesmith
Need help on this PR? Tag @codesmith with what you need.

  • Let Codesmith autofix CI failures and bot reviews

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@charlesrhoward charlesrhoward enabled auto-merge (squash) May 15, 2026 21:34
Copy link
Copy Markdown

@mogplex mogplex Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mogplex PR Review

Status: Attention needed

This is a clean, well-scoped security patch bump of Next.js from 16.0.10 to 16.2.6. The package.json and pnpm-lock.yaml changes are consistent and correct. There is one minor inaccuracy in the PR description worth noting, but it does not affect the correctness of the change. The PR is approve-ready.

1 finding was added inline.

View check run

Comment thread package.json
@@ -69,7 +69,7 @@
"input-otp": "1.4.1",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: PR description states incorrect previous version

The PR body says "next 16.2.3 → 16.2.6" but the actual previous version pinned in package.json (and the lockfile) was 16.0.10, not 16.2.3. This is a description-only inaccuracy — the code change itself is correct. No action required, but worth correcting the description for accurate audit trail purposes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant