Skip to content

build(deps): bump next from 16.2.12 to 16.3.3 in /frontend - #1631

Draft
dependabot[bot] wants to merge 2 commits into
autoresearch/frontend-sec-bumpfrom
dependabot/npm_and_yarn/frontend/next-16.3.3
Draft

build(deps): bump next from 16.2.12 to 16.3.3 in /frontend#1631
dependabot[bot] wants to merge 2 commits into
autoresearch/frontend-sec-bumpfrom
dependabot/npm_and_yarn/frontend/next-16.3.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Current authority — 2026-09-10

The Dependabot proposal was valid as a security signal against protected develop, but it is no longer a valid independent dependency owner. Canonical #1623 already carries Next.js 16.3.4, generated pnpm-lock updates, adjacent frontend security floors and lock/importer regression contracts. Merging the original 16.3.3 branch independently would reintroduce a lower Next.js version than the current canonical security owner.

This branch was repaired rather than simply closed: ordinary two-parent commit b032611... preserves the Dependabot proposal as first-parent provenance, adopts #1623 as second parent, and uses the exact #1623 tree. The branch advanced with force=false; no dependency-security source is copied or independently owned here.

Keep this PR Draft while #1623 remains unintegrated. It must not be counted as a separate security fix, version bump or release candidate. If #1623 advances, this provenance lane may ordinary-adopt the new canonical head while remaining zero-delta. Do not issue a Dependabot recreate/rebase command because that would restore the obsolete 16.3.3 delta.

Bumps [next](https://github.com/vercel/next.js) from 16.2.12 to 16.3.3.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.12...v16.3.3)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.3.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 9, 2026 23:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 18b80c7c-d951-4b90-9e43-9d5524792185

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Preserve Dependabot's 16.3.3 proposal as first-parent provenance while adopting #162317a7618, which already carries Next.js 16.3.4 and the reviewed dependency-security invariants. No downgrade delta remains.

Signed-off-by: Seongho Bae <me@seonghobae.me>
@seonghobae
seonghobae changed the base branch from develop to autoresearch/frontend-sec-bump September 10, 2026 00:51
@seonghobae
seonghobae marked this pull request as draft September 10, 2026 00:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant