build(deps): bump next from 16.2.12 to 16.3.3 in /frontend - #1631
Draft
dependabot[bot] wants to merge 2 commits into
Draft
build(deps): bump next from 16.2.12 to 16.3.3 in /frontend#1631dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [next](https://github.com/vercel/next.js) from 16.2.12 to 16.3.3. - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.2.12...v16.3.3) --- updated-dependencies: - dependency-name: next dependency-version: 16.3.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
changed the base branch from
develop
to
autoresearch/frontend-sec-bump
September 10, 2026 00:51
seonghobae
marked this pull request as draft
September 10, 2026 00:51
This was referenced Sep 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current authority — 2026-09-10
autoresearch/frontend-sec-bump@17a7618eda2b212b691f08fa936e042b34258fc93d22de2cfc1ba8a99b8127183cc74dd191a61444(next16.2.12 → 16.3.3)b0326119003a34f25dcb517964d0fe812b8427a0The Dependabot proposal was valid as a security signal against protected
develop, but it is no longer a valid independent dependency owner. Canonical #1623 already carries Next.js 16.3.4, generated pnpm-lock updates, adjacent frontend security floors and lock/importer regression contracts. Merging the original 16.3.3 branch independently would reintroduce a lower Next.js version than the current canonical security owner.This branch was repaired rather than simply closed: ordinary two-parent commit
b032611...preserves the Dependabot proposal as first-parent provenance, adopts #1623 as second parent, and uses the exact #1623 tree. The branch advanced withforce=false; no dependency-security source is copied or independently owned here.Keep this PR Draft while #1623 remains unintegrated. It must not be counted as a separate security fix, version bump or release candidate. If #1623 advances, this provenance lane may ordinary-adopt the new canonical head while remaining zero-delta. Do not issue a Dependabot recreate/rebase command because that would restore the obsolete 16.3.3 delta.