Skip to content

chore(web): update Next.js to 16.3.3 - #1619

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/update-next
Aug 27, 2026
Merged

chore(web): update Next.js to 16.3.3#1619
brendan-kellam merged 2 commits into
mainfrom
brendan/update-next

Conversation

@brendan-kellam

@brendan-kellam brendan-kellam commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Update Next.js from 16.3.1 to 16.3.3.
  • Refresh the lockfile so all Next.js resolution paths use 16.3.3.
  • Include the critical security fixes in the upstream 16.3.3 release.

Testing

  • yarn install --immutable
  • yarn workspace @sourcebot/web lint
  • yarn workspace @sourcebot/web test --run (1,437 tests passed)
  • yarn workspace @sourcebot/web build

Note

Low Risk
Patch-level framework upgrade with lockfile-only runtime changes; typical regression surface is build/routing but scope is limited to version pins.

Overview
Bumps the @sourcebot/web Next.js dependency from 16.3.1 to 16.3.3 and refreshes yarn.lock so resolved @next/env and platform SWC packages align with 16.3.3.

Documents the change under [Unreleased] → Fixed in CHANGELOG.md, citing upstream security fixes in 16.3.3. No application source changes beyond dependency metadata.

Reviewed by Cursor Bugbot for commit 5d06c22. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Updates Next.js from 16.3.1 to 16.3.3 in the web package to include critical security fixes from the upstream release.

  • Refreshes yarn.lock so all Next.js resolution paths use 16.3.3.
  • Verified with immutable install, lint, tests (1,437 pass), and build.

Written for commit 69381bd. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Updated Next.js to version 16.3.3, incorporating the latest upstream security fixes.
  • Documentation
    • Added an entry to the unreleased changelog documenting the update.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a881a76-21d4-42da-9eab-4b735f776bf6

📥 Commits

Reviewing files that changed from the base of the PR and between c07377b and 5d06c22.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/package.json

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.


Walkthrough

Changes

Dependency Update

Layer / File(s) Summary
Update next dependency version
packages/web/package.json, CHANGELOG.md
The next dependency was updated from ^16.3.1 to ^16.3.3. The upgrade was documented under the Unreleased Fixed section.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 5d06c

This PR updates Next.js to a security-fix patch release and refreshes its lockfile without application-code changes. It is merge-ready after normal checks and review, with no actionable merge-blocking risk remaining.

Suggested reviewers: msukkari

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: updating Next.js in the web package to version 16.3.3.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/update-next

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2173
Resolved (non-standard) 26
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.13 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (26)
Package Version Original Resolved Source
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-darwin 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-arm 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-arm64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-i686 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-x64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-arm64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-i686 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-x64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT npm registry metadata for the exact version + upstream repo LICENSE at tag 2.58.6 (Functional Source License 1.1, MIT Future License)
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/codemirror-lang-elixir LICENSE at tag v4.0.0) + LICENSE shipped in the 4.0.0 tarball
khroma 2.1.0 UNKNOWN MIT GitHub repo (fabiospampinato/khroma license) + license file shipped in the 2.1.0 tarball
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/lezer-elixir LICENSE at tag v1.1.2) + LICENSE shipped in the 1.1.2 tarball
map-stream 0.1.0 UNKNOWN MIT LICENCE shipped in the 0.1.0 tarball (MIT text); npm registry records MIT for sibling versions 0.0.5-0.0.7
memorystream 0.3.1 UNKNOWN MIT extracted from object: npm registry legacy "licenses" array [{"type":"MIT",...}]; confirmed by LICENSE in tarball
pause-stream 0.0.11 ["MIT", "Apache2"] (MIT OR Apache-2.0) extracted from object: npm "license" array ["MIT","Apache2"]; confirmed by LICENSE ("Dual Licensed MIT and Apache 2")
posthog-js 1.369.0 SEE LICENSE IN LICENSE (Apache-2.0 AND MIT) LICENSE shipped in tarball (Apache-2.0 primary + MIT for vendored code); matches npm registry SPDX for current releases
valid-url 1.0.9 UNKNOWN MIT GitHub repo (ogt/valid-url LICENSE) + LICENSE shipped in the 1.0.9 tarball

@brendan-kellam
brendan-kellam merged commit 16dbcf7 into main Aug 27, 2026
14 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/update-next branch August 27, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant