Skip to content

LOTTO v1.25.0 — Next.js 16.3.2, advisories cleared

Choose a tag to compare

@MattGeiger MattGeiger released this 26 Aug 23:09
· 71 commits to main since this release

LOTTO v1.25.0 upgrades Next.js from 16.0.10 to 16.3.2 and closes the remaining dependency advisories. The client bundle drops roughly 176 KB — 48 chunks / 3,394,148 bytes down to 41 chunks / 3,218,514 bytes.

Dependencies

  • next 16.0.10 → 16.3.2.
  • sharp → ^0.35.4. Next 16.3 bundles its own sharp 0.35.4, which reintroduced the libvips duplicate-class collision from v1.24.1 — but mirrored: the root copy sat on 0.34.5 (libvips 8.17.3) while Next resolved 8.18.6, loading two dylibs into one process. In v1.24.1 the fix was to revert; here it is to move forward.
  • nodemailer → ^8.0.11. Blocked in v1.24.1 when @auth/core required ^6.8.0; the beta.32 upgrade in v1.24.3 widened both Auth.js peer ranges to ^7.0.7 || ^8.0.5, opening the 8.x line. Resolves six of seven nodemailer advisories including the CVSS 7.5 addressparser DoS.
  • linkify-it needed no upgrade. The lockfile had pinned a stale markdown-it 14.2.0, holding linkify-it at 5.0.1; ordinary resolution moves to 14.3.0 and 5.0.2, which is patched. An override forcing markdown-it 15 was tried and reverted once the simpler resolution proved sufficient — tiptap-markdown declares ^14.1.0, so that pairing is untested upstream.

What remains

A single unfixed issue: nodemailer's message-level raw option bypassing disableFileAccess/disableUrlAccess, which needs 9.0.1+ and falls outside the Auth.js peer range. npm audit reports it as four entries because nodemailer 8 now satisfies that peer range and npm can traverse the edge to @auth/core, @auth/pg-adapter and next-auth — at 7.0.10 the mismatch hid it. Entry count went 2 → 4 while real vulnerabilities went 8 → 1. The count is the misleading figure. Not visitor-reachable: production requires Resend and never constructs an SMTP transport.

Fixed

  • 18 pre-existing TypeScript errors across 13 test files. Not introduced by the upgrade — the same 18 are present on 16.0.10, confirmed by running tsc against both dependency sets and diffing normalized error lists. Next 16.0.10's build silently skipped typechecking tests; 16.3.2 honours tsconfig's include. One was a real defect: appearance-logo-upload.test.tsx omitted a required templates prop. npx tsc --noEmit is clean for the first time.
  • Rendered Markdown links now look like links — blue and underlined, across Announcements, Help and Release Notes. Colour comes from a new brand-independent --link token: a link is a universal affordance, and a green link inside Lift Up's green body copy would carry no signal.
  • npm run dev works again on the iPadOS 15 floor. Next 16.3 ships a React dev build that calls eval(), and Safari 15 does not treat ws: as covered by connect-src 'self'. Both relaxations are development-only; production headers verified byte-identical.

Verification

789 tests across 109 files, tsc, lint, a production build and the legacy-bundle scan all pass. Because a framework upgrade rebuilds every client chunk, a static scan is not sufficient evidence for the support floor — verification was done on a simulated iPad mini 4 running iPadOS 15.4 with a custom appearance applied, in both dev and production builds, confirming hydration rather than merely that the page painted.

Full changelog: v1.24.3...v1.25.0