fix: bump next to 16.3.0 to remove vulnerable postcss/sharp deps - #3698
Draft
dielduarte wants to merge 1 commit into
Draft
fix: bump next to 16.3.0 to remove vulnerable postcss/sharp deps#3698dielduarte wants to merge 1 commit into
dielduarte wants to merge 1 commit into
Conversation
🦋 Changeset detectedLatest commit: 0805e1c The changes in this PR will be included in the next version bump. This PR includes changesets to release 3 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
commit: |
klotty
approved these changes
Aug 4, 2026
klotty
left a comment
There was a problem hiding this comment.
No issues found across 4 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Auto-approved: This update resolves high-severity security vulnerabilities by bumping the next dependency and includes a focused type fix for test compatibility.
Re-trigger cubic
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Redo of #3691, which was reverted in #3697 after the `tests` check failed on `canary`. That failure (`check-spam.spec.tsx` snapshot mismatch) was a SpamAssassin/DCC classification drift on an unrelated live external service — re-running it later against this same diff passed cleanly, and the code this PR touches has no path to that test's spam-checking feature. Opening as draft pending confirmation CI stays green before merging.
Fixes #3689
Verification
Test plan
Summary by cubic
Upgrade
nextto 16.3.0 to remove vulnerable transitivepostcssandsharpversions and keep fresh installs npm-audit clean. Also fixes a test-only typing issue surfaced by 16.3.0. Fixes #3689.Dependencies
next16.2.6 → 16.3.0 in the pnpm catalog and lockfile; adds a changeset for@react-email/uipatch release.postcss8.5.23 andsharp0.35.x, clearing 4 high-severity advisories.Bug Fixes
emitWarningcall handling inrun-bundled-code.spec.tsto satisfy stricter Node typings; behavior unchanged.Written for commit 0805e1c. Summary will update on new commits.