Skip to content

chore(deps)(deps): bump the minor-and-patch group across 1 directory with 2 updates - #264

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-769ccd7b6c
Oct 5, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-769ccd7b6c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 2 updates in the / directory: @next/third-parties and @opennextjs/cloudflare.

Updates @next/third-parties from 16.3.5 to 16.3.8

Release notes

Sourced from @​next/third-parties's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Updates @opennextjs/cloudflare from 1.20.6 to 1.20.7

Release notes

Sourced from @​opennextjs/cloudflare's releases.

@​opennextjs/cloudflare@​1.20.7

Patch Changes

  • #1403 dc3c0ab Thanks @​aa-sikkkk! - fix: replace the whole loadCustomCacheHandlers body so Next.js 16.3 chunks don't throw ReferenceError

    Next.js 16.3 rewrote loadCustomCacheHandlers: the declaration that binds cacheHandlers now also binds cacheMaxMemorySize, and the native method body consumes both. The composable cache patch replaced only that declaration, so on the minified runtime chunks (dist/compiled/next-server/*.runtime.prod.js) the surviving native code referenced bindings that were no longer declared. Every request to the Worker then failed with ReferenceError: <minified identifier> is not defined inside loadCustomCacheHandlers (site-wide 500s on Next.js 16.3.x), while builds stayed green because the unminified next-server.js short-circuits on if (!cacheHandlers) return before the orphaned binding is read.

    The patch now replaces the whole method body while preserving its signature and wires the composable cache registry to the static require() as before, so no native reference to a dropped binding can survive. The rule still matches pre-16.3 chunks, so older Next.js versions are unaffected.

  • #1399 2b3e3a1 Thanks @​JT1974! - fix: throw MODULE_NOT_FOUND from the stub of a missing optional dependency

    With React 18, every Pages Router page rendered by the Worker failed with TypeError: Cannot read properties of undefined (reading 'contexts'), caused by Error: Missing optional dependency "react-dom/server.edge". React 18 has no react-dom/server.edge, and Next.js falls back to react-dom/server.browser only when the error carries the MODULE_NOT_FOUND code. The stub now sets that code, so the fallback works again.

  • #1406 8ea9eb9 Thanks @​mgarbacz! - fix: only rename esbuild's __require helper, not __require properties

    Restoring esbuild's __require helper to a bare require was a text replacement over the whole bundle, so it also rewrote unrelated __require members. @rollup/plugin-commonjs emits exports.__require lazy-init wrappers, whose declarations the replacement never matched — leaving the two halves disagreeing and throwing TypeError: __webpack_require__(...).require is not a function when such a package was imported during SSR. Packages built that way (for example smartystreets-javascript-sdk) 500'd every route. The rename now skips property accesses.

  • #1404 ca4415b Thanks @​vicb! - chore: require Next.js 15.5.26 or 16.3.6

    Raise the supported Next.js version floor to 15.5.26 and 16.3.6. Next.js 16.2.0 through 16.3.5 are affected by the critical next/og remote code execution vulnerability CVE-2026-94545.

  • #1404 ca4415b Thanks @​vicb! - chore: bump @opennextjs/aws to 4.1.6

    See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.6

Changelog

Sourced from @​opennextjs/cloudflare's changelog.

1.20.7

Patch Changes

  • #1403 dc3c0ab Thanks @​aa-sikkkk! - fix: replace the whole loadCustomCacheHandlers body so Next.js 16.3 chunks don't throw ReferenceError

    Next.js 16.3 rewrote loadCustomCacheHandlers: the declaration that binds cacheHandlers now also binds cacheMaxMemorySize, and the native method body consumes both. The composable cache patch replaced only that declaration, so on the minified runtime chunks (dist/compiled/next-server/*.runtime.prod.js) the surviving native code referenced bindings that were no longer declared. Every request to the Worker then failed with ReferenceError: <minified identifier> is not defined inside loadCustomCacheHandlers (site-wide 500s on Next.js 16.3.x), while builds stayed green because the unminified next-server.js short-circuits on if (!cacheHandlers) return before the orphaned binding is read.

    The patch now replaces the whole method body while preserving its signature and wires the composable cache registry to the static require() as before, so no native reference to a dropped binding can survive. The rule still matches pre-16.3 chunks, so older Next.js versions are unaffected.

  • #1399 2b3e3a1 Thanks @​JT1974! - fix: throw MODULE_NOT_FOUND from the stub of a missing optional dependency

    With React 18, every Pages Router page rendered by the Worker failed with TypeError: Cannot read properties of undefined (reading 'contexts'), caused by Error: Missing optional dependency "react-dom/server.edge". React 18 has no react-dom/server.edge, and Next.js falls back to react-dom/server.browser only when the error carries the MODULE_NOT_FOUND code. The stub now sets that code, so the fallback works again.

  • #1406 8ea9eb9 Thanks @​mgarbacz! - fix: only rename esbuild's __require helper, not __require properties

    Restoring esbuild's __require helper to a bare require was a text replacement over the whole bundle, so it also rewrote unrelated __require members. @rollup/plugin-commonjs emits exports.__require lazy-init wrappers, whose declarations the replacement never matched — leaving the two halves disagreeing and throwing TypeError: __webpack_require__(...).require is not a function when such a package was imported during SSR. Packages built that way (for example smartystreets-javascript-sdk) 500'd every route. The rename now skips property accesses.

  • #1404 ca4415b Thanks @​vicb! - chore: require Next.js 15.5.26 or 16.3.6

    Raise the supported Next.js version floor to 15.5.26 and 16.3.6. Next.js 16.2.0 through 16.3.5 are affected by the critical next/og remote code execution vulnerability CVE-2026-94545.

  • #1404 ca4415b Thanks @​vicb! - chore: bump @opennextjs/aws to 4.1.6

    See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.6

Commits
  • 4636385 Version Packages (#1388)
  • 8ea9eb9 fix: only rename esbuild's __require helper, not __require properties (#1...
  • ca4415b Bump Next and AWS (#1404)
  • dc3c0ab fix composable cache patch for Next.js 16.3 minified runtime (#1403)
  • 2b3e3a1 fix: throw MODULE_NOT_FOUND from the stub of a missing optional dependency ...
  • ee0a415 chore: bump @opennextjs/aws to 4.1.5 (#1387)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…with 2 updates

Bumps the minor-and-patch group with 2 updates in the / directory: [@next/third-parties](https://github.com/vercel/next.js/tree/HEAD/packages/third-parties) and [@opennextjs/cloudflare](https://github.com/opennextjs/opennextjs-cloudflare/tree/HEAD/packages/cloudflare).


Updates `@next/third-parties` from 16.3.5 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.8/packages/third-parties)

Updates `@opennextjs/cloudflare` from 1.20.6 to 1.20.7
- [Release notes](https://github.com/opennextjs/opennextjs-cloudflare/releases)
- [Changelog](https://github.com/opennextjs/opennextjs-cloudflare/blob/main/packages/cloudflare/CHANGELOG.md)
- [Commits](https://github.com/opennextjs/opennextjs-cloudflare/commits/@opennextjs/cloudflare@1.20.7/packages/cloudflare)

---
updated-dependencies:
- dependency-name: "@next/third-parties"
  dependency-version: 16.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@opennextjs/cloudflare"
  dependency-version: 1.20.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Preview deployment

Status URL
Skipped -

Commit: afd8e6c
Updated: 2026-10-05T06:09:51.275Z

Reason: Dependabot-triggered workflows do not have access to repository secrets in this workflow.

If you want a preview deployment, please ask a maintainer to run this from a branch within the main repository.

@github-actions
github-actions Bot merged commit 20542f7 into main Oct 5, 2026
9 of 11 checks passed
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/minor-and-patch-769ccd7b6c branch October 5, 2026 06:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants