Repository navigation
LOTTO v1.25.0 — Next.js 16.3.2, advisories cleared
LOTTO v1.25.0 upgrades Next.js from 16.0.10 to 16.3.2 and closes the remaining dependency advisories. The client bundle drops roughly 176 KB — 48 chunks / 3,394,148 bytes down to 41 chunks / 3,218,514 bytes.
Dependencies
next16.0.10 → 16.3.2.sharp→^0.35.4. Next 16.3 bundles its ownsharp0.35.4, which reintroduced the libvips duplicate-class collision from v1.24.1 — but mirrored: the root copy sat on 0.34.5 (libvips 8.17.3) while Next resolved 8.18.6, loading two dylibs into one process. In v1.24.1 the fix was to revert; here it is to move forward.nodemailer→^8.0.11. Blocked in v1.24.1 when@auth/corerequired^6.8.0; the beta.32 upgrade in v1.24.3 widened both Auth.js peer ranges to^7.0.7 || ^8.0.5, opening the 8.x line. Resolves six of seven nodemailer advisories including the CVSS 7.5addressparserDoS.linkify-itneeded no upgrade. The lockfile had pinned a stalemarkdown-it14.2.0, holdinglinkify-itat 5.0.1; ordinary resolution moves to 14.3.0 and 5.0.2, which is patched. An override forcingmarkdown-it15 was tried and reverted once the simpler resolution proved sufficient —tiptap-markdowndeclares^14.1.0, so that pairing is untested upstream.
What remains
A single unfixed issue: nodemailer's message-level raw option bypassing disableFileAccess/disableUrlAccess, which needs 9.0.1+ and falls outside the Auth.js peer range. npm audit reports it as four entries because nodemailer 8 now satisfies that peer range and npm can traverse the edge to @auth/core, @auth/pg-adapter and next-auth — at 7.0.10 the mismatch hid it. Entry count went 2 → 4 while real vulnerabilities went 8 → 1. The count is the misleading figure. Not visitor-reachable: production requires Resend and never constructs an SMTP transport.
Fixed
- 18 pre-existing TypeScript errors across 13 test files. Not introduced by the upgrade — the same 18 are present on 16.0.10, confirmed by running
tscagainst both dependency sets and diffing normalized error lists. Next 16.0.10's build silently skipped typechecking tests; 16.3.2 honourstsconfig'sinclude. One was a real defect:appearance-logo-upload.test.tsxomitted a requiredtemplatesprop.npx tsc --noEmitis clean for the first time. - Rendered Markdown links now look like links — blue and underlined, across Announcements, Help and Release Notes. Colour comes from a new brand-independent
--linktoken: a link is a universal affordance, and a green link inside Lift Up's green body copy would carry no signal. npm run devworks again on the iPadOS 15 floor. Next 16.3 ships a React dev build that callseval(), and Safari 15 does not treatws:as covered byconnect-src 'self'. Both relaxations are development-only; production headers verified byte-identical.
Verification
789 tests across 109 files, tsc, lint, a production build and the legacy-bundle scan all pass. Because a framework upgrade rebuilds every client chunk, a static scan is not sufficient evidence for the support floor — verification was done on a simulated iPad mini 4 running iPadOS 15.4 with a custom appearance applied, in both dev and production builds, confirming hydration rather than merely that the page painted.
Full changelog: v1.24.3...v1.25.0