Skip to content

build(deps): bump next from 16.1.6 to 16.1.7#3016

Closed
dependabot[bot] wants to merge 1 commit intoalphafrom
dependabot/npm_and_yarn/next-16.1.7
Closed

build(deps): bump next from 16.1.6 to 16.1.7#3016
dependabot[bot] wants to merge 1 commit intoalphafrom
dependabot/npm_and_yarn/next-16.1.7

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 17, 2026

Bumps next from 16.1.6 to 16.1.7.

Release notes

Sourced from next's releases.

v16.1.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [Cache Components] Prevent streaming fetch calls from hanging in dev (#89194)
  • Apply server actions transform to node_modules in route handlers (#89380)
  • ensure maxPostponedStateSize is always respected (See: CVE-2026-27979)
  • feat(next/image): add lru disk cache and images.maximumDiskCacheSize (See: CVE-2026-27980)
  • Allow blocking cross-site dev-only websocket connections from privacy-sensitive origins (See: CVE-2026-27977)
  • Disallow Server Action submissions from privacy-sensitive contexts by default (See: CVE-2026-27978)
  • fix: patch http-proxy to prevent request smuggling in rewrites (See: CVE-2026-29057)

Credits

Huge thanks to @​unstubbable, @​styfle, @​eps1lon, and @​ztanner for helping!

Commits
  • bdf3e35 v16.1.7
  • dc98c04 [backport]: fix: patch http-proxy to prevent request smuggling in rewrites (#...
  • 9023c0a [backport] Disallow Server Action submissions from privacy-sensitive contexts...
  • 36a97b9 Allow blocking cross-site dev-only websocket connections from privacy-sensiti...
  • 93c3993 [backport]: feat(next/image): add lru disk cache and `images.maximumDiskCache...
  • c68d62d Backport documentation fixes for 16.1.x (#90655)
  • 5214ac1 [backport]: ensure maxPostponedStateSize is always respected (#90060) (#90471)
  • c95e357 Backport/docs fixes 16.1.x (#90125)
  • cba6144 [backport] Apply server actions transform to node_modules in route handlers...
  • 3db9063 [backport] [Cache Components] Prevent streaming fetch calls from hanging in d...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 17, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Mar 17, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​16.1.6 ⏵ 16.1.762100 +691 +19770

View full report

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.1.7 branch from 55b523d to c9fc19b Compare March 18, 2026 17:39
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.1.7 branch from c9fc19b to 85b4adf Compare March 19, 2026 14:43
@dependabot dependabot Bot requested a review from a team as a code owner March 19, 2026 14:43
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.1.7 branch from 85b4adf to a68087c Compare March 24, 2026 10:21
@maxgfr maxgfr removed the request for review from a team March 24, 2026 11:21
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.1.7 branch from a68087c to 11dc674 Compare March 30, 2026 16:07
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.1.7 branch from 11dc674 to 2f879dd Compare April 1, 2026 16:29
@dependabot dependabot Bot changed the title chore(deps): bump next from 16.1.6 to 16.1.7 build(deps): bump next from 16.1.6 to 16.1.7 Apr 9, 2026
Bumps [next](https://github.com/vercel/next.js) from 16.1.6 to 16.1.7.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](vercel/next.js@v16.1.6...v16.1.7)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.1.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.1.7 branch from 2f879dd to 8473f58 Compare April 9, 2026 16:49
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 11, 2026

Superseded by #3199.

@dependabot dependabot Bot closed this Apr 11, 2026
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/next-16.1.7 branch April 11, 2026 00:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants