Skip to content

feat(deps): update nextjs monorepo (16.3.8 → 16.4.0) - #1187

Merged
joryirving merged 1 commit into
mainfrom
renovate/nextjs-monorepo
Oct 6, 2026
Merged

joryirving merged 1 commit into
mainfrom
renovate/nextjs-monorepo

Conversation

@its-miso

@its-miso its-miso Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
eslint-config-next (source) 16.3.8 → 16.4.0 age adoption passing confidence
next (source) 16.3.8 → 16.4.0 age adoption passing confidence

Release Notes

vercel/next.js (eslint-config-next)

v16.4.0

Compare Source

vercel/next.js (next)

v16.4.0

Compare Source


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-miso
its-miso Bot requested a review from joryirving as a code owner October 6, 2026 19:23
@its-miso its-miso Bot added the type/minor label Oct 6, 2026

@its-saffron its-saffron Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M3 (anthropic) — primary route · pr-reviewer-action v3.3.0

Partial coverage: required-check coverage is incomplete — this review did not resolve every required check and must not be read as a complete pass.

Findings (1 blocker, 1 major, 1 info)

Severity Location Finding
🛑 Blocker package-lock.json CI gate `npm audit` is in a terminal failure state on the bump head; the lockfile change should not merge with the blocking audit gate red.
⚠️ Major package-lock.json The user-mandated 'run full test suite after upgrade' check is unresolved: Tests, Coverage, smoke, and Docker Build jobs are all still pending in CI for this head.
Info package-lock.json vercel/next.js release page shows no published stable `v16.4.0` tag yet (only `16.4.0-canary.59` through `16.4.0-canary.63` after `v16.3.8`); the compare metadata reports `status: diverged`. This may be a premature Renovate bump target — worth confirming with the Renovate source before merging.

Recommendation: request_changes

This is a Renovate-driven bump of the Next.js monorepo from 16.3.8 to 16.4.0. The diff itself is well-formed and internally consistent, and the project's existing protections (package-overrides, npm audit --omit=dev --include=prod, sharp override) keep the bump safe against the historical advisory classes. The blocker is not the diff — it's the CI gate state: the npm audit job has reached a terminal failure state on the head commit, and the user-mandated "full test suite" check has not been observed-completed (Tests / Coverage / smoke / Docker Build all still pending). A version bump to next/eslint-config-next/@next/* should not merge while the blocking audit gate is red.

Change-by-change findings

  • Lockfile-only scope (claim 1) — held. PR metadata, working tree, and the diff confirm only package-lock.json is modified. No source, config, docs, or manifest file outside the lockfile moves.
  • next 16.3.8 → 16.4.0 (claim 2) — held. Resolved at package-lock.json:8677. The package.json range is ^16.2.7, which admits 16.4.0 without drift.
  • eslint-config-next 16.3.8 → 16.4.0 (claim 3) — held. Resolved at package-lock.json:6121. Range ^16.2.6 in package.json:devDependencies admits 16.4.0. The peerDependencies block still requires eslint: ">=9.0.0", and the project pins eslint: "^10.0.0", which is compatible with the canary.61 changelog note "eslint-config-next: support ESLint 10" found in the linked release page.
  • @next/* lockstep (claim 4) — held. All ten @next/* entries (@next/env, @next/eslint-plugin-next, plus the eight @next/swc-* platform binaries) are at 16.4.0 and resolve from registry.npmjs.org. No leftover 16.3.8 strings remain in package-lock.json.
  • Transitive lint range bumps (claim 5) — held. eslint-plugin-react-hooks resolves to 7.1.1 (satisfies the new ^7.1.0) and typescript-eslint resolves to 8.70.0 (satisfies the new ^8.56.0). Both are dev-only and the project's top-level manifest has no conflicting constraint.

Why I'm not approving despite the lockfile being clean

  • CI npm audit is FAILING on the bump head. That is a terminal state for an authoritative CI gate, not a tail-cut. Per AGENTS.md ("Lint/typecheck blocks CI; must pass") the security-audit.yaml workflow runs npm run audit, and package-audit.test.ts enforces the --omit=dev --include=prod scoping — so a failing audit here is the production-scope audit surface going red. This must be resolved before merge, either by (i) landing a fix that addresses the audit finding, or (ii) confirming the finding is the known dev-only advisory that escapes the gate and updating the gate accordingly.
  • Full test suite has not run on head. Tests, Coverage, smoke, and the two Docker Build jobs are still pending. The reviewer must not infer these passed from a truncated corpus — the must_check "run full test suite after upgrade" is unresolved until observed.

Sources

  • Renovate PR body and merge-confidence badges (included in PR corpus)
  • vercel/next.js release page: https://github.com/vercel/next.js/releases (shows v16.4.0-canary.* and v16.3.8 but no v16.4.0 stable tag — compare metadata reports status: diverged)
  • Compare: https://github.com/vercel/next.js/compare/v16.3.8...v16.4.0 (1,073 ahead, 63 behind)
  • Project files: package.json, package-lock.json, AGENTS.md, .github/ai-review-rules.md, package-audit.test.ts

Standards Compliance

  • AGENTS.md says "Lint/typecheck blocks CI; must pass." On this head, lint/typecheck/build/workflow-lint/database integrations all show success — that portion of the standards is satisfied.
  • AGENTS.md / .github/ai-review-rules.md (token hygiene) — not applicable; this PR touches no tokens, auth, or secrets.
  • The project's documented Renovate convention keeps a Renovate PR's scope tight (lockfile-only for a next monorepo bump); the PR honors that.

Unknowns or Needs Verification

  • The exact npm audit failure on this head (advisory id, severity, transitive path) is not in the corpus — only that the check reached terminal failure. The maintainer should paste the audit output, or the gate must be re-run green, before this can be approved.
  • Whether next@16.4.0 introduces any consumer-visible Next.js API change beyond the eslint-config-next ESLint 10 peer entry. The release page shows only canary.59–canary.63 between 16.3.8 and now, and no stable v16.4.0 tag is published — so "16.4.0 stable is unverified-released". The compare metadata's diverged / behind_by: 63 is consistent with that state.
  • Tests / Coverage / smoke / Docker Build have not yet produced observed results in the corpus.

Unaddressed required checks

The classifier marked these checks as required for this PR's risk profile, but the review does not resolve or disposition them:

  • check for breaking API changes in updated dependencies
  • run full test suite after upgrade

@joryirving
joryirving merged commit 890a8fa into main Oct 6, 2026
13 of 14 checks passed
@joryirving
joryirving deleted the renovate/nextjs-monorepo branch October 6, 2026 20:02
@its-miso its-miso Bot mentioned this pull request Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant