What vercel/next.js shipped
Written by FoxPlug from public releases; not affiliated with Next.js. An automatic summary of the public release, pull request and commit data of github.com/vercel/next.js. Next.js did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Week of September 21, 2026
What shipped
- v16.4.0-canary.51 released with security upgrade insights in DevTools and focused npm advisories. Release
- Developers running next dev with agentic auto-upgrade enabled now see browser reminders when their Next.js version has a security advisory. Pull request #99002
- Advisory checks now query only the installed version and upgrade candidates instead of sending bulk audit requests. Pull request #99222
- v16.4.0-canary.50 released with prerelease security upgrade support and agentic upgrades without Git. Release
- Apps without a Git repository can now use agentic upgrades by checking for duplicate work using available repository capabilities. Pull request #99217
- Dynamically imported local-only ESM modules no longer create duplicate runtime identities through facade splits. Pull request #99285
- Fixed Server Actions hanging after navigation to PPR pages by properly handling postponed state in POST requests. Pull request #99252
- Edge App Router SSR now respects the same metadata streaming policy as Node SSR for user-agent-based bot requests. Pull request #99128
- v16.4.0-canary.46 released with experimental custom webpack support reverted and Turbopack improvements. Release
- CI for branch-based PR stacks now uses a read-only TypeScript gate instead of Graphite-specific optimization. Pull request #99086
Why it matters
This week's changes focus on security upgrade workflows, PPR page navigation reliability, and metadata streaming correctness. Developers get better visibility into security advisories and can upgrade without Git, while builds become more robust with fixes to ESM module loading and Edge SSR metadata handling.
Changelog entry
- Show security upgrade insights in DevTools (#99002) Release
- Use focused npm advisories and nudge only for ready upgrades (#99222) Pull request #99222
- Explain prerelease security upgrade limits (#99230) Pull request #99230
- Support latest agentic upgrades on prerelease channels (#99223) Pull request #99223
- Allow agentic upgrades without Git (#99217) Pull request #99217
- Avoid facade splits solely for export mangling (#99285) Pull request #99285
- Allow webpack loaders to cross filesystem roots when reading dependencies (#99202) Pull request #99202
- Fix Server Actions hanging after navigation to PPR pages (#99252) Pull request #99252
- Respect metadata streaming policy in Edge SSR (#99128) Pull request #99128
- Revert experimental custom webpack support (#99227) Pull request #99227
v16.4.0-canary.51 ships security upgrade insights in DevTools, npm advisory improvements, and PPR page navigation fixes. Agentic upgrades now work without Git.
v16.4.0-canary.51 brings security upgrade insights directly into DevTools with focused npm advisories. Developers can now use agentic upgrades even without Git, and we've fixed Server Actions hanging on PPR page navigation. Edge SSR now properly respects metadata streaming policies, and ESM module loading is more reliable.