Skip to content

chore: bump next.js from 16.2.7 to 16.3.0 - #17633

Merged
nathanlentz merged 3 commits into
mainfrom
chore/next-16-3-bump
Aug 4, 2026
Merged

chore: bump next.js from 16.2.7 to 16.3.0#17633
nathanlentz merged 3 commits into
mainfrom
chore/next-16-3-bump

Conversation

@nathanlentz

@nathanlentz nathanlentz commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Bumps the Next.js version used in the monorepo from 16.2.7 to 16.3.0, along with the pinned @next/env and @next/eslint-plugin-next packages.

Stacked on #17632 — review that one first.

TypeScript detection

Next.js 16.3 changes the default of experimental.useTypeScriptCli to true. In CLI mode Next looks for a typescript/bin/tsc binary instead of the compiler API at typescript/lib/typescript.js:

const typescriptCliPackage = { file: 'typescript/bin/tsc', pkg: 'typescript', exportsRestrict: true }

This repo aliases typescript to @typescript/typescript6, which only ships a tsc6 bin. getTypeScriptPackageInfo reads packageJson.bin.tsc, gets undefined, and Next reports the package as missing — then tries to run pnpm add --save-dev typescript at the workspace root, which fails:

It looks like you're trying to use TypeScript but do not have the required package(s) installed.
[ERR_PNPM_ADDING_TO_ROOT] Running this command will add the dependency to the workspace root...

Both next.config.mjs and test/next.config.mjs now set useTypeScriptCli: false so Next keeps using the compiler API, which the alias does provide.

Scope

Templates stay on 16.2.7 and are bumped separately, to keep this diff reviewable.

Testing

  • @next/env resolves at 16.3.0 from both packages/payload and test; @next/eslint-plugin-next resolves at 16.3.0 from packages/next.

@nathanlentz
nathanlentz requested a review from denolfe as a code owner August 4, 2026 18:55
@socket-security

socket-security Bot commented Aug 4, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​next/​eslint-plugin-next@​16.3.01001007397100
Added@​next/​bundle-analyzer@​16.3.01001008997100

View full report

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

📦 esbuild Bundle Analysis for payload

This analysis was generated by esbuild-bundle-analyzer. 🤖

Meta File Out File Size (raw) Note
packages/next/meta_index.json esbuild/index.js 201.89 KB 🆕 Added
packages/payload/meta_index.json esbuild/index.js 1.40 MB 🆕 Added
packages/payload/meta_shared.json esbuild/exports/shared.js 213.18 KB 🆕 Added
packages/richtext-lexical/meta_client.json esbuild/exports/client_optimized/index.js 285.63 KB 🆕 Added
packages/ui/meta_client.json esbuild/exports/client_optimized/index.js 36.54 KB 🆕 Added
packages/ui/meta_shared.json esbuild/exports/shared_optimized/index.js 18.95 KB 🆕 Added
Largest paths These visualization shows top 20 largest paths in the bundle.

Meta file: packages/next/meta_index.json, Out file: esbuild/index.js

Path Size
../../node_modules ${{\color{Goldenrod}{ ████████████████████████▋ }}}$ 98.9%, 197.86 KB
dist/adapters/router.js ${{\color{Goldenrod}{ }}}$ 0.4%, 718 B
dist/adapters/server.js ${{\color{Goldenrod}{ }}}$ 0.3%, 533 B
dist/adapters/layout.js ${{\color{Goldenrod}{ }}}$ 0.3%, 526 B
dist/adapters/views.js ${{\color{Goldenrod}{ }}}$ 0.2%, 409 B
dist/esbuildEntry.js ${{\color{Goldenrod}{ }}}$ 0.0%, 0 B

Meta file: packages/payload/meta_index.json, Out file: esbuild/index.js

Path Size
../../node_modules ${{\color{Goldenrod}{ █████████████████ }}}$ 68.0%, 944.34 KB
dist/fields/hooks ${{\color{Goldenrod}{ ▊ }}}$ 3.2%, 44.38 KB
dist/collections/operations ${{\color{Goldenrod}{ ▊ }}}$ 3.1%, 42.75 KB
dist/utilities/configToJSONSchema.js ${{\color{Goldenrod}{ ▎ }}}$ 1.2%, 15.99 KB
dist/auth/operations ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 15.62 KB
dist/queues/operations ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 14.29 KB
dist/fields/config ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 13.63 KB
dist/globals/operations ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 13.38 KB
dist/fields/validations.js ${{\color{Goldenrod}{ ▏ }}}$ 0.8%, 10.69 KB
dist/bin/generateImportMap ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 9.84 KB
dist/collections/config ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 9.60 KB
dist/config/orderable ${{\color{Goldenrod}{ ▏ }}}$ 0.6%, 8.06 KB
dist/uploads/fetchAPI-multipart ${{\color{Goldenrod}{ ▏ }}}$ 0.6%, 7.84 KB
dist/hierarchy/utils ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.64 KB
dist/database/migrations ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.55 KB
dist/index.js ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.44 KB
dist/config/sanitize.js ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.06 KB
dist/collections/endpoints ${{\color{Goldenrod}{ }}}$ 0.4%, 6.12 KB
dist/uploads/endpoints ${{\color{Goldenrod}{ }}}$ 0.4%, 5.56 KB
dist/utilities/telemetry ${{\color{Goldenrod}{ }}}$ 0.4%, 5.43 KB
(other) ${{\color{Goldenrod}{ ████████ }}}$ 32.0%, 445.10 KB

Meta file: packages/payload/meta_shared.json, Out file: esbuild/exports/shared.js

Path Size
../../node_modules ${{\color{Goldenrod}{ █████████████████▉ }}}$ 71.9%, 150.13 KB
dist/fields/validations.js ${{\color{Goldenrod}{ █▎ }}}$ 5.1%, 10.69 KB
dist/fields/config ${{\color{Goldenrod}{ ▋ }}}$ 2.8%, 5.83 KB
dist/utilities/traverseFields.js ${{\color{Goldenrod}{ ▌ }}}$ 2.1%, 4.45 KB
dist/collections/config ${{\color{Goldenrod}{ ▍ }}}$ 1.6%, 3.33 KB
dist/config/orderable ${{\color{Goldenrod}{ ▍ }}}$ 1.5%, 3.13 KB
dist/fields/baseFields ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 2.79 KB
dist/utilities/deepCopyObject.js ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 2.69 KB
dist/config/client.js ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 2.68 KB
dist/auth/cookies.js ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 1.55 KB
dist/utilities/flattenTopLevelFields.js ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 1.41 KB
dist/utilities/getVersionsConfig.js ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 1.04 KB
dist/globals/config ${{\color{Goldenrod}{ }}}$ 0.4%, 939 B
dist/utilities/flattenAllFields.js ${{\color{Goldenrod}{ }}}$ 0.4%, 793 B
dist/utilities/unflatten.js ${{\color{Goldenrod}{ }}}$ 0.4%, 779 B
dist/utilities/sanitizeUserDataForEmail.js ${{\color{Goldenrod}{ }}}$ 0.3%, 713 B
dist/auth/extractJWT.js ${{\color{Goldenrod}{ }}}$ 0.3%, 696 B
dist/utilities/getFieldPermissions.js ${{\color{Goldenrod}{ }}}$ 0.3%, 651 B
dist/errors/ValidationError.js ${{\color{Goldenrod}{ }}}$ 0.3%, 577 B
dist/bin/generateImportMap ${{\color{Goldenrod}{ }}}$ 0.3%, 561 B
(other) ${{\color{Goldenrod}{ ███████ }}}$ 28.1%, 58.57 KB

Meta file: packages/richtext-lexical/meta_client.json, Out file: esbuild/exports/client_optimized/index.js

Path Size
dist/features/blocks ${{\color{Goldenrod}{ ███▎ }}}$ 13.2%, 37.20 KB
dist/lexical/ui ${{\color{Goldenrod}{ ███ }}}$ 12.1%, 34.20 KB
dist/lexical/plugins ${{\color{Goldenrod}{ ██▉ }}}$ 11.7%, 33.01 KB
dist/features/table ${{\color{Goldenrod}{ ██▍ }}}$ 9.6%, 27.22 KB
dist/features/link ${{\color{Goldenrod}{ █▋ }}}$ 6.7%, 18.82 KB
dist/features/toolbars ${{\color{Goldenrod}{ █▍ }}}$ 5.9%, 16.58 KB
dist/features/upload ${{\color{Goldenrod}{ █▎ }}}$ 5.1%, 14.28 KB
dist/features/textState ${{\color{Goldenrod}{ ▉ }}}$ 3.9%, 11.08 KB
dist/lexical/utils ${{\color{Goldenrod}{ ▉ }}}$ 3.5%, 10.02 KB
dist/features/relationship ${{\color{Goldenrod}{ ▊ }}}$ 3.4%, 9.61 KB
dist/features/converters ${{\color{Goldenrod}{ ▊ }}}$ 3.0%, 8.36 KB
dist/utilities/fieldsDrawer ${{\color{Goldenrod}{ ▋ }}}$ 2.9%, 8.12 KB
dist/features/debug ${{\color{Goldenrod}{ ▋ }}}$ 2.6%, 7.40 KB
dist/lexical/config ${{\color{Goldenrod}{ ▍ }}}$ 1.8%, 5.14 KB
dist/features/lists ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 3.64 KB
dist/features/format ${{\color{Goldenrod}{ ▎ }}}$ 1.2%, 3.28 KB
dist/lexical/LexicalEditor.js ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 3.23 KB
dist/features/horizontalRule ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 3.18 KB
dist/field/Field.js ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 2.88 KB
dist/lexical/nodes ${{\color{Goldenrod}{ ▏ }}}$ 0.9%, 2.66 KB
(other) ${{\color{Goldenrod}{ █████████████████████▋ }}}$ 86.8%, 245.23 KB

Meta file: packages/ui/meta_client.json, Out file: esbuild/exports/client_optimized/index.js

Path Size
dist/exports/client ${{\color{Goldenrod}{ █████████████████████████ }}}$ 100.0%, 26.90 KB

Meta file: packages/ui/meta_shared.json, Out file: esbuild/exports/shared_optimized/index.js

Path Size
dist/graphics/Logo ${{\color{Goldenrod}{ ███████▋ }}}$ 30.5%, 5.57 KB
../../node_modules ${{\color{Goldenrod}{ ███▌ }}}$ 14.5%, 2.65 KB
dist/graphics/Icon ${{\color{Goldenrod}{ ██ }}}$ 8.3%, 1.51 KB
dist/utilities/formatDocTitle ${{\color{Goldenrod}{ █▊ }}}$ 7.2%, 1.32 KB
dist/providers/TableColumns ${{\color{Goldenrod}{ █▏ }}}$ 4.7%, 866 B
dist/utilities/getGlobalData.js ${{\color{Goldenrod}{ █ }}}$ 4.2%, 762 B
dist/utilities/api.js ${{\color{Goldenrod}{ █ }}}$ 4.1%, 756 B
dist/utilities/groupNavItems.js ${{\color{Goldenrod}{ █ }}}$ 4.1%, 745 B
dist/elements/Translation ${{\color{Goldenrod}{ ▋ }}}$ 2.7%, 493 B
dist/utilities/handleTakeOver.js ${{\color{Goldenrod}{ ▌ }}}$ 2.4%, 440 B
dist/utilities/traverseForLocalizedFields.js ${{\color{Goldenrod}{ ▌ }}}$ 2.3%, 419 B
dist/elements/withMergedProps ${{\color{Goldenrod}{ ▍ }}}$ 1.9%, 339 B
dist/utilities/getNavGroups.js ${{\color{Goldenrod}{ ▍ }}}$ 1.9%, 338 B
dist/utilities/getVisibleEntities.js ${{\color{Goldenrod}{ ▍ }}}$ 1.8%, 329 B
dist/elements/WithServerSideProps ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 232 B
dist/layouts/Root ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 230 B
dist/utilities/handleGoBack.js ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 180 B
dist/fields/mergeFieldStyles.js ${{\color{Goldenrod}{ ▏ }}}$ 0.9%, 158 B
dist/forms/Form ${{\color{Goldenrod}{ ▏ }}}$ 0.8%, 152 B
dist/utilities/handleBackToDashboard.js ${{\color{Goldenrod}{ ▏ }}}$ 0.8%, 152 B
(other) ${{\color{Goldenrod}{ █████████████████▍ }}}$ 69.5%, 12.68 KB
Details

Next to the size is how much the size has increased or decreased compared with the base branch of this PR.

  • ‼️: Size increased by 20% or more. Special attention should be given to this.
  • ⚠️: Size increased in acceptable range (lower than 20%).
  • ✅: No change or even downsized.
  • 🗑️: The out file is deleted: not found in base branch.
  • 🆕: The out file is newly found: will be added to base branch.

AlessioGr
AlessioGr previously approved these changes Aug 4, 2026
denolfe
denolfe previously approved these changes Aug 4, 2026
Base automatically changed from fix/nextjs-16-3-hmr-endpoint-rename to main August 4, 2026 21:10
Bumps the Next.js version used in the monorepo, along with the pinned
@next/env and @next/eslint-plugin-next packages.

Next.js 16.3 changes the default of experimental.useTypeScriptCli to true,
which makes Next look for a `typescript/bin/tsc` binary instead of the
compiler API. This repo aliases `typescript` to @typescript/typescript6,
which only ships a `tsc6` bin, so Next reported TypeScript as missing and
tried to install it at the workspace root. Both next.config.mjs files now
set the flag to false so Next keeps using the compiler API.

Templates stay on 16.2.7 and are bumped separately.
Nesting @Keyframes inside a style rule is invalid CSS - only conditional
group rules can nest. Next.js 16.3 ships a stricter CSS parser that rejects
the rule and drops the read-only editor styles.

Hoist the keyframes to the top level of the layer and scope its name, since
hoisting makes the name global.
The canary line renamed the HMR path at 16.2.1-canary.2, a month before
16.3.0-canary.0 existed, while the 16.2 patches were cut from a branch
without the rename. So 16.2.1-canary.26 serves /_next/hmr and 16.2.7
serves /_next/webpack-hmr. The 16.3 boundary holds for stable releases
only.
@nathanlentz
nathanlentz merged commit c7de1c4 into main Aug 4, 2026
177 checks passed
@nathanlentz
nathanlentz deleted the chore/next-16-3-bump branch August 4, 2026 22:30
nathanlentz added a commit that referenced this pull request Aug 5, 2026
)

Backport of #17632 and #17633 to `3.x`.

### What?

Payload's config hot reload in development stopped working on Next.js
16.3. Adding a collection or a field had no effect until the dev server
was restarted.

Next.js 16.3 renamed the dev HMR WebSocket endpoint:

- Old: `/_next/webpack-hmr` — [`router-server.ts#L859-L860` on
`v16.2.7`](https://github.com/vercel/next.js/blob/v16.2.7/packages/next/src/server/lib/router-server.ts#L859-L860)
- New: `/_next/hmr` — [`router-server.ts#L946-L947` on
`v16.3.0`](https://github.com/vercel/next.js/blob/v16.3.0/packages/next/src/server/lib/router-server.ts#L946-L947)

The client moved with it, in
[`client/dev/hot-reloader/app/web-socket.ts`](https://github.com/vercel/next.js/blob/v16.3.0/packages/next/src/client/dev/hot-reloader/app/web-socket.ts).
There is no alias in either direction: `/_next/webpack-hmr` appears only
in old docs inside the 16.3.0 build, and `/_next/hmr` does not appear
anywhere in 16.2.7.

This branch also bumps the monorepo to Next.js 16.3.0. `3.x` was on a
mix of `16.2.3` (root) and `16.2.6` (`test/`, `packages/next`).

### Why?

Payload hardcoded `/_next/webpack-hmr`. On 16.3 the upgrade request no
longer matched, so the socket never opened. The failure was invisible
because the `onerror` handler and the surrounding `try` block both
swallow errors, so `cached.reload` stayed `false` and the reload never
ran. No type regeneration, no import map regeneration, and no client
config cache clear.

[Related Vercel PR](vercel/next.js#91415), which
went into canary several months ago.

### How?

Read the installed Next.js version and connect to the path that version
serves: `/_next/hmr` at 16.3 and above, `/_next/webpack-hmr` below it.
One socket, no configuration, correct across supported Next.js versions.

```
/_next/hmr             => open
/_next/webpack-hmr     => no response after 8s
/_next/not-a-real-path => no response after 8s
```

A wrong path never errors and never closes, so a fallback triggered by
failure would hang forever on Next 16.2 and below and break HMR for
every older version.

`PAYLOAD_HMR_URL_OVERRIDE` keeps working and is still used verbatim,
skipping version detection.

### Differences from the changes on `main`

- `main` extracted a `defaultNextJsDevReloadStrategy` into
`nextJsDevReloadStrategy.ts`. `3.x` has no `DevReloadStrategy`
abstraction, so only the URL selection is extracted, as
`getNextJsHMRURL.ts`. The socket handling stays inline in `getPayload`.
- `main` sets `experimental.useTypeScriptCli: false` in both
`next.config.mjs` files, because it aliases `typescript` to
`@typescript/typescript6`, which ships no `tsc` bin for Next 16.3's new
CLI mode to find. `3.x` uses plain `typescript@5.7.3`, so the alias
problem does not exist and the setting is not needed.
- `main` added `minimumReleaseAgeExclude` entries to
`pnpm-workspace.yaml`. `3.x` does not set `minimumReleaseAge`.
- `packages/payload` keeps `@next/env` at `^15.1.5` rather than pinning
`16.3.0`, since that range also serves apps on Next 15.
- Templates are unchanged, as on `main` (coming in later PR)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants