Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 1, 2025

Bumps next from 15.3.2 to 15.4.5.

Release notes

Sourced from next's releases.

v15.4.5

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • Fix API stripping JSON incorrectly (#82062)
  • Fix i18n fallback: false collision (#82158)
  • Revert "Fix tracing of server actions imported by client components (#82167)
  • Ensure setAssetPrefix updates config instance (#82165)
  • Turbopack: update mimalloc (#82166)
  • fix(next/image): fix image-optimizer.ts headers (#82175)
  • fix(next/image): improve and simplify detect-content-type (#82174)

Credits

Huge thanks to @​ijjk, @​sokra, and @​styfle for helping!

v15.4.4

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • Fix dynamicParams false layout case in dev (#82026)
  • Turbopack: fix scope hoisting variable renaming bug (#81640)
  • Upgrade to swc v33 (#81750)
  • Revert "[metadata] use https protocol for schema urls" (#81934)

Credits

Huge thanks to @​bgw @​mischnic @​huozhi @​lukesandberg and @​ijjk for helping!

v15.4.3

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • Turbopack: fix dist dir on Windows (#81758)

Credits

Huge thanks to @​mischnic for helping!

v15.4.2

[!NOTE]

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [next](https://github.com/vercel/next.js) from 15.3.2 to 15.4.5.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](vercel/next.js@v15.3.2...v15.4.5)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 15.4.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Update one or more dependencies version javascript Pull requests that update Javascript code minor Increment the minor version when merged labels Aug 1, 2025
@vercel
Copy link

vercel bot commented Aug 1, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
next-forge ✅ Ready (Inspect) Visit Preview 💬 Add feedback Aug 1, 2025 4:23am
next-forge-api ❌ Failed (Inspect) Aug 1, 2025 4:23am
next-forge-app ❌ Failed (Inspect) Aug 1, 2025 4:23am
next-forge-storybook ✅ Ready (Inspect) Visit Preview 💬 Add feedback Aug 1, 2025 4:23am

@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​negotiator@​0.6.3 ⏵ 0.6.41001006779 -2100
Updatedultracite@​4.2.5 ⏵ 4.2.1393 -110071 +196 +1100
Addedfumadocs-core@​15.6.7981007496100
Updated@​prisma/​nextjs-monorepo-workaround-plugin@​6.8.2 ⏵ 6.13.0100 +11007598100
Updatedposthog-node@​4.17.2 ⏵ 4.18.0100 +110076 +199 +1100
Updatedvitest@​3.1.4 ⏵ 3.2.4971007799 +1100
Updated@​logtail/​next@​0.2.0 ⏵ 0.2.194 +110080 +186100
Added@​tailwindcss/​postcss@​4.1.111001008099100
Addedpostcss@​8.5.6991008188100
Addedsonner@​2.0.61001008190100
Addednext@​15.4.582100909870
Updated@​turbo/​gen@​2.5.3 ⏵ 2.5.5991008296 +5100
Updated@​ai-sdk/​openai@​1.3.22 ⏵ 1.3.23100 +110084 +197 +1100
Addedtailwindcss@​4.1.111001008498100
Addedtailwind-merge@​3.3.11001008593100
Updatedconcurrently@​9.1.2 ⏵ 9.2.099 +1100100 +185100
Updatedturbo@​2.5.3 ⏵ 2.5.5100 +110085 +198 +5100
Updatedws@​8.18.2 ⏵ 8.18.399 +110010086100
Updated@​t3-oss/​env-nextjs@​0.13.4 ⏵ 0.13.810010086 +791 -3100
Updated@​liveblocks/​client@​2.24.2 ⏵ 2.24.31001008798 +2100
Updated@​t3-oss/​env-core@​0.13.4 ⏵ 0.13.8100 +110087 +791 -3100
Updatedchromatic@​12.0.0 ⏵ 12.2.099 +110087 +199 -1100
Updatedimport-in-the-middle@​1.13.2 ⏵ 1.14.2100 +110010088 -180
Updated@​neondatabase/​serverless@​1.0.0 ⏵ 1.0.199 +110010090100
Updated@​sentry/​nextjs@​9.22.0 ⏵ 9.44.09510090 +1100 +1100
Updated@​chromatic-com/​storybook@​3.2.6 ⏵ 3.2.798 +110090 +1100 +2100
Addedsharp@​0.34.39110010090100
Added@​testing-library/​dom@​10.4.19910010091100
Updated@​liveblocks/​node@​2.24.2 ⏵ 2.24.399 +11009198 +1100
Updated@​knocklabs/​react@​0.7.11 ⏵ 0.7.279910091 +197 +1100
Addedreact-resizable-panels@​3.0.410010010091100
Updatedbasehub@​8.2.7 ⏵ 8.2.1192 +110094 +196 +2100
Updated@​clerk/​themes@​2.2.46 ⏵ 2.4.410010092100100
See 21 more rows in the dashboard

View full report

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 8, 2025

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/next-15.4.5 branch October 8, 2025 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Update one or more dependencies version javascript Pull requests that update Javascript code minor Increment the minor version when merged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants