Skip to content

Bump next from 16.3.5 to 16.3.6 - #2562

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/next-16.3.6
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/next-16.3.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps next from 16.3.5 to 16.3.6.

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code patch labels Oct 1, 2026
Bumps [next](https://github.com/vercel/next.js) from 16.3.5 to 16.3.6.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump next from 16.3.3 to 16.3.6 Bump next from 16.3.5 to 16.3.6 Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/next-16.3.6 branch from ebd3116 to 0c77b09 Compare October 5, 2026 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants