Repository navigation
feat(deps): update nextjs monorepo (16.3.8 → 16.4.0) - #1187
Conversation
There was a problem hiding this comment.
AI Automated Review
Full PR review.
Analysis engine: MiniMax-M3 (anthropic) — primary route · pr-reviewer-action v3.3.0
Partial coverage: required-check coverage is incomplete — this review did not resolve every required check and must not be read as a complete pass.
Findings (1 blocker, 1 major, 1 info)
| Severity | Location | Finding |
|---|---|---|
| 🛑 Blocker | package-lock.json |
CI gate `npm audit` is in a terminal failure state on the bump head; the lockfile change should not merge with the blocking audit gate red. |
package-lock.json |
The user-mandated 'run full test suite after upgrade' check is unresolved: Tests, Coverage, smoke, and Docker Build jobs are all still pending in CI for this head. | |
| Info | package-lock.json |
vercel/next.js release page shows no published stable `v16.4.0` tag yet (only `16.4.0-canary.59` through `16.4.0-canary.63` after `v16.3.8`); the compare metadata reports `status: diverged`. This may be a premature Renovate bump target — worth confirming with the Renovate source before merging. |
Recommendation: request_changes
This is a Renovate-driven bump of the Next.js monorepo from 16.3.8 to 16.4.0. The diff itself is well-formed and internally consistent, and the project's existing protections (package-overrides, npm audit --omit=dev --include=prod, sharp override) keep the bump safe against the historical advisory classes. The blocker is not the diff — it's the CI gate state: the npm audit job has reached a terminal failure state on the head commit, and the user-mandated "full test suite" check has not been observed-completed (Tests / Coverage / smoke / Docker Build all still pending). A version bump to next/eslint-config-next/@next/* should not merge while the blocking audit gate is red.
Change-by-change findings
- Lockfile-only scope (claim 1) — held. PR metadata, working tree, and the diff confirm only
package-lock.jsonis modified. No source, config, docs, or manifest file outside the lockfile moves. next16.3.8 → 16.4.0 (claim 2) — held. Resolved atpackage-lock.json:8677. Thepackage.jsonrange is^16.2.7, which admits 16.4.0 without drift.eslint-config-next16.3.8 → 16.4.0 (claim 3) — held. Resolved atpackage-lock.json:6121. Range^16.2.6inpackage.json:devDependenciesadmits 16.4.0. ThepeerDependenciesblock still requireseslint: ">=9.0.0", and the project pinseslint: "^10.0.0", which is compatible with the canary.61 changelog note "eslint-config-next: support ESLint 10" found in the linked release page.@next/*lockstep (claim 4) — held. All ten@next/*entries (@next/env,@next/eslint-plugin-next, plus the eight@next/swc-*platform binaries) are at16.4.0and resolve fromregistry.npmjs.org. No leftover16.3.8strings remain inpackage-lock.json.- Transitive lint range bumps (claim 5) — held.
eslint-plugin-react-hooksresolves to7.1.1(satisfies the new^7.1.0) andtypescript-eslintresolves to8.70.0(satisfies the new^8.56.0). Both are dev-only and the project's top-level manifest has no conflicting constraint.
Why I'm not approving despite the lockfile being clean
- CI
npm auditis FAILING on the bump head. That is a terminal state for an authoritative CI gate, not a tail-cut. PerAGENTS.md("Lint/typecheck blocks CI; must pass") thesecurity-audit.yamlworkflow runsnpm run audit, andpackage-audit.test.tsenforces the--omit=dev --include=prodscoping — so a failing audit here is the production-scope audit surface going red. This must be resolved before merge, either by (i) landing a fix that addresses the audit finding, or (ii) confirming the finding is the known dev-only advisory that escapes the gate and updating the gate accordingly. - Full test suite has not run on head. Tests, Coverage, smoke, and the two Docker Build jobs are still pending. The reviewer must not infer these passed from a truncated corpus — the must_check "run full test suite after upgrade" is unresolved until observed.
Sources
- Renovate PR body and merge-confidence badges (included in PR corpus)
vercel/next.jsrelease page:https://github.com/vercel/next.js/releases(showsv16.4.0-canary.*andv16.3.8but nov16.4.0stable tag — compare metadata reportsstatus: diverged)- Compare:
https://github.com/vercel/next.js/compare/v16.3.8...v16.4.0(1,073 ahead, 63 behind) - Project files:
package.json,package-lock.json,AGENTS.md,.github/ai-review-rules.md,package-audit.test.ts
Standards Compliance
AGENTS.mdsays "Lint/typecheck blocks CI; must pass." On this head, lint/typecheck/build/workflow-lint/database integrations all show success — that portion of the standards is satisfied.AGENTS.md/.github/ai-review-rules.md(token hygiene) — not applicable; this PR touches no tokens, auth, or secrets.- The project's documented Renovate convention keeps a Renovate PR's scope tight (lockfile-only for a
nextmonorepo bump); the PR honors that.
Unknowns or Needs Verification
- The exact
npm auditfailure on this head (advisory id, severity, transitive path) is not in the corpus — only that the check reached terminalfailure. The maintainer should paste the audit output, or the gate must be re-run green, before this can be approved. - Whether
next@16.4.0introduces any consumer-visible Next.js API change beyond theeslint-config-nextESLint 10 peer entry. The release page shows only canary.59–canary.63 between16.3.8and now, and no stablev16.4.0tag is published — so "16.4.0 stable is unverified-released". The compare metadata'sdiverged / behind_by: 63is consistent with that state. - Tests / Coverage / smoke / Docker Build have not yet produced observed results in the corpus.
Unaddressed required checks
The classifier marked these checks as required for this PR's risk profile, but the review does not resolve or disposition them:
- check for breaking API changes in updated dependencies
- run full test suite after upgrade
This PR contains the following updates:
16.3.8→16.4.016.3.8→16.4.0Release Notes
vercel/next.js (eslint-config-next)
v16.4.0Compare Source
vercel/next.js (next)
v16.4.0Compare Source
Configuration
📅 Schedule: (in timezone America/Edmonton)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate CLI.