Qentrah
Projects
Guides

Dependency compatibility and audit

View as Markdown

Next.js and React are pinned to the latest stable versions available during this migration; the lockfile fixes transitive versions too. ESLint is pinned to 9.39.5, the latest compatible 9.x release: Next.js 16.3.8’s React/import/accessibility plugins still declare ESLint 9 peer ranges, and ESLint 10.12.0 failed with scopeManager.addGlobals is not a function. ESLint 9 is now out of upstream support; update it when Next.js’s bundled lint plugins support ESLint 10.

The production audit reports zero vulnerabilities. The full audit currently reports five high-severity entries stemming from one unpatched development-only braces advisory through Next.js’s ESLint plugin (fast-glob → micromatch → braces). The upstream advisory lists no patched release. These packages are lint tooling, not production dependencies. Do not use npm audit fix --force, which proposes downgrading the Next.js ESLint configuration to version 14.2.35.

Source captured: 2026-10-11