Skip to content

chore(deps): bump next from 16.1.5 to 16.1.7 in /packages/react-sdk/dev/nextjs-bootstrap-demo#560

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/packages/react-sdk/dev/nextjs-bootstrap-demo/next-16.1.7
Open

chore(deps): bump next from 16.1.5 to 16.1.7 in /packages/react-sdk/dev/nextjs-bootstrap-demo#560
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/packages/react-sdk/dev/nextjs-bootstrap-demo/next-16.1.7

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 17, 2026

Bumps next from 16.1.5 to 16.1.7.

Release notes

Sourced from next's releases.

v16.1.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [Cache Components] Prevent streaming fetch calls from hanging in dev (#89194)
  • Apply server actions transform to node_modules in route handlers (#89380)
  • ensure maxPostponedStateSize is always respected (See: CVE-2026-27979)
  • feat(next/image): add lru disk cache and images.maximumDiskCacheSize (See: CVE-2026-27980)
  • Allow blocking cross-site dev-only websocket connections from privacy-sensitive origins (See: CVE-2026-27977)
  • Disallow Server Action submissions from privacy-sensitive contexts by default (See: CVE-2026-27978)
  • fix: patch http-proxy to prevent request smuggling in rewrites (See: CVE-2026-29057)

Credits

Huge thanks to @​unstubbable, @​styfle, @​eps1lon, and @​ztanner for helping!

Commits
  • bdf3e35 v16.1.7
  • dc98c04 [backport]: fix: patch http-proxy to prevent request smuggling in rewrites (#...
  • 9023c0a [backport] Disallow Server Action submissions from privacy-sensitive contexts...
  • 36a97b9 Allow blocking cross-site dev-only websocket connections from privacy-sensiti...
  • 93c3993 [backport]: feat(next/image): add lru disk cache and `images.maximumDiskCache...
  • c68d62d Backport documentation fixes for 16.1.x (#90655)
  • 5214ac1 [backport]: ensure maxPostponedStateSize is always respected (#90060) (#90471)
  • c95e357 Backport/docs fixes 16.1.x (#90125)
  • cba6144 [backport] Apply server actions transform to node_modules in route handlers...
  • 3db9063 [backport] [Cache Components] Prevent streaming fetch calls from hanging in d...
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 17, 2026
@github-actions github-actions bot enabled auto-merge March 17, 2026 22:50
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/packages/react-sdk/dev/nextjs-bootstrap-demo/next-16.1.7 branch 9 times, most recently from be3fb81 to 0a931be Compare March 25, 2026 22:58
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/packages/react-sdk/dev/nextjs-bootstrap-demo/next-16.1.7 branch 2 times, most recently from d91e8f8 to 9fee459 Compare March 27, 2026 01:27
Bumps [next](https://github.com/vercel/next.js) from 16.1.5 to 16.1.7.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](vercel/next.js@v16.1.5...v16.1.7)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.1.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/packages/react-sdk/dev/nextjs-bootstrap-demo/next-16.1.7 branch from 9fee459 to 36dc30a Compare March 27, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants