Skip to content

Backport #3071: fix: upgrade next to 16.2.11 to address CVE-2026-64641#3073

Merged
VaguelySerious merged 2 commits into
stablefrom
backport/pr-3071-to-stable
Jul 23, 2026
Merged

Backport #3071: fix: upgrade next to 16.2.11 to address CVE-2026-64641#3073
VaguelySerious merged 2 commits into
stablefrom
backport/pr-3071-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3071 to stable (backport job run).

AI recommendation: This is a security-driven dependency bump (next → 16.2.11 for CVE-2026-64641) touching packages/next and workbench apps that exist on stable, which squarely matches the backport criteria for dependency bumps and fixes affecting both branches. The only stable-unmaintained file touched is docs/package.json, which the backport tooling auto-resolves in favor of stable.

Merge conflicts were resolved by AI (opencode with anthropic/claude-fable-5). Please review the conflict resolution carefully before merging.

Signed-off-by: Nathan Rajlich <n@n8.io>
@changeset-bot

changeset-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 99afd7b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
Name Type
@workflow/next Patch
workflow Patch
@workflow/world-testing Patch
@workflow/core Patch
@workflow/builders Patch
@workflow/cli Patch
@workflow/nitro Patch
@workflow/vitest Patch
@workflow/web-shared Patch
@workflow/web Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
example-nextjs-workflow-turbopack Ready Ready Preview, Comment Jul 23, 2026 10:35pm
example-nextjs-workflow-webpack Ready Ready Preview, Comment Jul 23, 2026 10:35pm
example-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-astro-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-express-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-fastify-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-hono-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-nestjs-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-nitro-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-nuxt-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-sveltekit-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-tanstack-start-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workbench-vite-workflow Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workflow-swc-playground Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workflow-tarballs Ready Ready Preview, Comment Jul 23, 2026 10:35pm
workflow-web Ready Ready Preview, Comment Jul 23, 2026 10:35pm
1 Skipped Deployment
Project Deployment Actions Updated (UTC)
workflow-docs Skipped Skipped Jul 23, 2026 10:35pm

@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

🧪 E2E Test Results

Some tests failed

Summary

Passed Failed Skipped Total
❌ ▲ Vercel Production 1076 1 78 1155
✅ 💻 Local Development 1174 0 86 1260
✅ 📦 Local Production 1174 0 86 1260
✅ 🐘 Local Postgres 1174 0 86 1260
✅ 🪟 Windows 105 0 0 105
❌ 🌍 Community Worlds 83 101 9 193
✅ 📋 Other 594 0 36 630
Total 5380 102 381 5863

❌ Failed Tests

▲ Vercel Production (1 failed)

fastify (1 failed):

  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KY8HV1M40YHWSCBXDK5E38YH | 🔍 observability
🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KY8HTPE689X4Y1WP9DYEGJ16
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KY8HV1M40YHWSCBXDK5E38YH
  • sleepingWorkflow | wrun_01KY8HW131DJCW8D7QB5J61GJB
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KY8J3FQJRRVZ9GKXP6R9V8Q7
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KY8J3V7KPZQRV1PBXQ1FKWQ6
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KY8J4219XBSD0V3CM4HAJHX6
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KY8J4FVWHXFCJZN8NKSPZ70G
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KY8J58MCEVBQ3SKKZD19NG80
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KY8J5CY79YBWZHSJKEZ37T9R
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KY8J5JDB8T1EVYX9WD9GEF6D
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KY8J5QA1BE73P2ETNEXQ2TVH
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KY8J5ZBMK3Z0MAGHXG9TE8X5
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KY8JBDRF8PHABSCYEJSSRSSM

turso (83 failed):

  • addTenWorkflow | wrun_01KY8HSFGPENAFQYBCR2NTSVXA
  • addTenWorkflow | wrun_01KY8HSFGPENAFQYBCR2NTSVXA
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KY8HTQ0R24KAGC82C42HAWPN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KY8HSR8FSG8KD0RVXZSEESRX
  • promiseRaceWorkflow | wrun_01KY8HSWT50RNSWF694629DFWK
  • promiseAnyWorkflow | wrun_01KY8HSYYXQAQ4QWW0RWC9KSGH
  • importedStepOnlyWorkflow | wrun_01KY8HV1W8KFN8BQB90FR3177Z
  • readableStreamWorkflow | wrun_01KY8HT0X71BVTXT8DMR6Q0GRS
  • hookWorkflow | wrun_01KY8HTG7T7CYTQV4M22WCA4MZ
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KY8HTPE689X4Y1WP9DYEGJ16
  • webhookWorkflow | wrun_01KY8HTVA25ETH2YV5FR7PHK0A
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KY8HV1M40YHWSCBXDK5E38YH
  • sleepingWorkflow | wrun_01KY8HW131DJCW8D7QB5J61GJB
  • parallelSleepWorkflow | wrun_01KY8HWGDY1HPWT6A9XHTB0JJB
  • sleepWinsRaceWorkflow | wrun_01KY8HWMM5S1Y2BF06HB2DDKXH
  • stepWinsRaceWorkflow | wrun_01KY8HWQPTK0FW4CPTWEPBJRBT
  • nullByteWorkflow | wrun_01KY8HWTRV30Q0MQ4MAT9ZRKE6
  • workflowAndStepMetadataWorkflow | wrun_01KY8HWWXP0TXNBXAXD4RYJ74V
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KY8HZ5Q6C55YDK00D6N28WV6
  • writableForwardedFromWorkflowWorkflow | wrun_01KY8HZK8SPHMJ1HVGRBXRN0PQ
  • writableForwardedFromStepWorkflow | wrun_01KY8HZQ6DZFWPT6AN4ZT9X338
  • fetchWorkflow | wrun_01KY8HZTPTXQZ6KH25FHQR98YH
  • promiseRaceStressTestWorkflow | wrun_01KY8HZXVYV6MP5198TCBHE7HN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KY8J34W4YTMN4H73567CC92E
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KY8J3FQJRRVZ9GKXP6R9V8Q7
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KY8J3V7KPZQRV1PBXQ1FKWQ6
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KY8J3XECNTAXF5QW2QNKW8AC
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KY8J3ZR76RH7DZ89CNGAMH4H
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KY8J4219XBSD0V3CM4HAJHX6
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KY8J4FVWHXFCJZN8NKSPZ70G
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KY8J58MCEVBQ3SKKZD19NG80
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KY8J5CY79YBWZHSJKEZ37T9R
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KY8J5JDB8T1EVYX9WD9GEF6D
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KY8J5QA1BE73P2ETNEXQ2TVH
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KY8J5ZBMK3Z0MAGHXG9TE8X5
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KY8J65HF1EBX33B5ZDYERY8A
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KY8J6KPYTE0Y6JMV3YQFGB7A
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KY8J6VXY2XEVCKH361AHVA6K
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KY8J70VP457JXDMBKT99P2V7
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KY8J72VC243YG83SQP1511PJ
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KY8J7N2JET0Q3HXF40TWPSRH
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KY8J7T4MSMA3K6V53X8DXMJR
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KY8J80HPCXFE1CVQBC8YC4NT
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KY8J86XTPDWHDHRD5G72CDQ1
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KY8J8DGXP4EQY2JDQQMCC954
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KY8J8M0QN5FHX6X0QK1AZNYZ
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KY8J8TDNE7Q9G1XCXVQN2XCQ
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KY8J961K0Q5DWEHBNX2W39BR
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KY8J9EDYAFWBA7H6S2TV3ZF0
  • cancelRun - cancelling a running workflow | wrun_01KY8J9MQ9ZZ0END8Y4ERGZW77
  • cancelRun via CLI - cancelling a running workflow | wrun_01KY8J9RX98QT9K577FSZ222B5
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KY8J9ZRT4JX0WF07E8ZJNC43
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KY8JAEVEFQS8XPVSH5GKTDF5
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KY8JART96B0R48MKW01V6SZW
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KY8JB3BKF2ZM5BVPKZ590KD6
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KY8JB9QY7YXE35J0PDH3Q8Z4
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KY8JBBSH0K9NHZX8NPNRYPAZ
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KY8JBDRF8PHABSCYEJSSRSSM

Details by Category

❌ ▲ Vercel Production
App Passed Failed Skipped
✅ astro 97 0 8
✅ example 97 0 8
✅ express 97 0 8
❌ fastify 96 1 8
✅ hono 97 0 8
✅ nextjs-turbopack 102 0 3
✅ nextjs-webpack 102 0 3
✅ nitro 97 0 8
✅ nuxt 97 0 8
✅ sveltekit 97 0 8
✅ vite 97 0 8
✅ 💻 Local Development
App Passed Failed Skipped
✅ astro-stable 99 0 6
✅ express-stable 99 0 6
✅ fastify-stable 99 0 6
✅ hono-stable 99 0 6
✅ nextjs-turbopack-canary 86 0 19
✅ nextjs-turbopack-stable 105 0 0
✅ nextjs-webpack-canary 86 0 19
✅ nextjs-webpack-stable 105 0 0
✅ nitro-stable 99 0 6
✅ nuxt-stable 99 0 6
✅ sveltekit-stable 99 0 6
✅ vite-stable 99 0 6
✅ 📦 Local Production
App Passed Failed Skipped
✅ astro-stable 99 0 6
✅ express-stable 99 0 6
✅ fastify-stable 99 0 6
✅ hono-stable 99 0 6
✅ nextjs-turbopack-canary 86 0 19
✅ nextjs-turbopack-stable 105 0 0
✅ nextjs-webpack-canary 86 0 19
✅ nextjs-webpack-stable 105 0 0
✅ nitro-stable 99 0 6
✅ nuxt-stable 99 0 6
✅ sveltekit-stable 99 0 6
✅ vite-stable 99 0 6
✅ 🐘 Local Postgres
App Passed Failed Skipped
✅ astro-stable 99 0 6
✅ express-stable 99 0 6
✅ fastify-stable 99 0 6
✅ hono-stable 99 0 6
✅ nextjs-turbopack-canary 86 0 19
✅ nextjs-turbopack-stable 105 0 0
✅ nextjs-webpack-canary 86 0 19
✅ nextjs-webpack-stable 105 0 0
✅ nitro-stable 99 0 6
✅ nuxt-stable 99 0 6
✅ sveltekit-stable 99 0 6
✅ vite-stable 99 0 6
✅ 🪟 Windows
App Passed Failed Skipped
✅ nextjs-turbopack 105 0 0
❌ 🌍 Community Worlds
App Passed Failed Skipped
✅ mongodb-dev 4 0 3
✅ redis-dev 4 0 3
❌ redis 68 18 0
✅ turso-dev 4 0 3
❌ turso 3 83 0
✅ 📋 Other
App Passed Failed Skipped
✅ e2e-local-dev-nest-stable 99 0 6
✅ e2e-local-dev-tanstack-start-stable 99 0 6
✅ e2e-local-postgres-nest-stable 99 0 6
✅ e2e-local-postgres-tanstack-start-stable 99 0 6
✅ e2e-local-prod-nest-stable 99 0 6
✅ e2e-local-prod-tanstack-start-stable 99 0 6

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

@VaguelySerious
VaguelySerious enabled auto-merge (squash) July 23, 2026 22:22

@vercel vercel Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional Suggestion:

Unpinned "monaco-editor": "latest" in swc-playground re-resolved to 0.56.0, whose restructured ESM export paths break the deep imports monaco-vim@0.4.4 relies on, failing the Turbopack production build.

Fix on Vercel

…ed to 0.56.0, whose restructured ESM export paths break the deep imports `monaco-vim@0.4.4` relies on, failing the Turbopack production build.

This commit fixes the issue reported at workbench/swc-playground/package.json:21

## Bug

`workbench/swc-playground/package.json` declared `"monaco-editor": "latest"`. When this PR bumped `next` (`16.2.1` → `16.2.11`) in the same `package.json`, pnpm re-resolved the lockfile and the floating `latest` spec for `monaco-editor` drifted from `0.55.1` to `0.56.0`.

The build log confirms this in the install phase:

```
- monaco-editor 0.55.1
+ monaco-editor 0.56.0
```

`monaco-editor@0.56.0` restructured its ESM export paths, so the deep imports that `monaco-vim@0.4.4` performs no longer resolve, and the Turbopack production build fails:

```
./node_modules/.pnpm/monaco-vim@0.4.4_monaco-editor@0.56.0/node_modules/monaco-vim/dist/index.mjs
Module not found: Can't resolve 'monaco-editor/esm/vs/editor/common/commands/shiftCommand'
Module not found: Can't resolve 'monaco-editor/esm/vs/editor/editor.api'
```

`monaco-vim` is pulled in through `workbench/swc-playground/components/editor.tsx` (dynamic `import('monaco-vim')` for vim mode).

### Trigger
Any production build of the `workflow-sdk-compiler-playground` app with the re-resolved lockfile: `next build` → Turbopack tries to bundle `monaco-vim@0.4.4`, whose `monaco-editor/esm/...` deep imports don't exist in `0.56.0`. The parent commit (before this PR) resolved `monaco-editor@0.55.1` and built fine, so this is a regression introduced purely by the lockfile re-resolution.

## Fix

1. Pinned `"monaco-editor": "0.55.1"` in `workbench/swc-playground/package.json` (the previously-working version that provides the ESM paths `monaco-vim@0.4.4` expects).
2. Regenerated `pnpm-lock.yaml` (`pnpm install --lockfile-only`), which reverts `monaco-editor` back to `0.55.1` everywhere (importer spec/version, `@monaco-editor/react` and `monaco-vim` peer resolutions, and the package/snapshot entries).

The lockfile diff is cleanly scoped: only `monaco-editor` and its legitimately version-tied transitive dependency `dompurify` change (`0.55.1` uses `dompurify@3.2.7` vs `0.56.0`'s `dompurify@3.4.8`), exactly matching the pre-regression lockfile state. No unrelated packages were touched.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: VaguelySerious <mittgfu@gmail.com>
@VaguelySerious
VaguelySerious disabled auto-merge July 23, 2026 22:45
@VaguelySerious
VaguelySerious merged commit 58fb594 into stable Jul 23, 2026
91 of 96 checks passed
@VaguelySerious
VaguelySerious deleted the backport/pr-3071-to-stable branch July 23, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant