Skip to content

chore: bump next to 16.3.6 - #4409

Merged
pranaygp merged 2 commits into
mainfrom
bump-next-dependency
Sep 25, 2026
Merged

pranaygp merged 2 commits into
mainfrom
bump-next-dependency

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Routine patch bump of the remaining Next.js pins in the repo from 16.3.4 to
16.3.6, finishing the alignment the docs app started in #4395.

Pin Before After
@workflow/next (devDependency) 16.3.4 16.3.6
workbench/nextjs-turbopack 16.3.4 16.3.6
workbench/nextjs-webpack 16.3.4 16.3.6
workbench/swc-playground 16.3.4 16.3.6
docs 16.3.6 (unchanged)

16.3.6 is the newest release in the 16.3 line, so every workspace project now
resolves to a single copy of next and the lockfile carries one next@16.3.x
entry instead of two.

The next peerDependency on @workflow/next is deliberately left at
>13 — only the pinned devDependency moves, so the range consumers are
resolved against is unchanged.

Lockfile churn

Beyond the four pins, the diff is dedupe: the @next/env and @next/swc-*
16.3.4 platform packages drop out (their 16.3.6 counterparts were already in
the tree via docs), the next@16.3.4 snapshots collapse onto the 16.3.6 ones,
and @vercel/analytics's peer key re-points at 16.3.6.

One unrelated-looking line moves with it: @vitest/coverage-v8@4.1.10's
vitest peer key flips from the @types/node@22.19.0 variant to the
@types/node@24.6.2 one. next participates in @types/node peer
resolution, so removing the 16.3.4 variants changed which variant pnpm picks
as canonical for that already-ambiguous peer. It is a types-only key
selection with no runtime effect.

To confirm the lockfile holds nothing beyond what the pins imply, I
re-resolved main's lockfile with pnpm install --lockfile-only in a clean
worktree carrying only the four package.json edits; the result is
byte-identical to the lockfile here.

Verification

All run locally against this branch:

  • pnpm build — 28/28 tasks
  • pnpm typecheck — 43/43 tasks
  • pnpm test — 53/53 tasks
  • pnpm lint — exit 0 (pre-existing warnings only)
  • pnpm --filter nextjs-turbopack build
  • pnpm --filter nextjs-webpack build
  • pnpm --filter workflow-sdk-compiler-playground build

🤖 Generated with Claude Code

Align the remaining Next.js pins in the repo on 16.3.6, which the docs app
already moved to in #4395:

- `@workflow/next`'s `next` devDependency
- `workbench/nextjs-turbopack`
- `workbench/nextjs-webpack`
- `workbench/swc-playground`

The `next` peerDependency on `@workflow/next` stays `>13`; only the pinned
devDependency and the app pins move.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

Co-Authored-By: Pranay Prakash <1797812+pranaygp@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 25, 2026 04:00
@pranaygp
pranaygp requested a review from a team as a code owner September 25, 2026 04:00
@changeset-bot

changeset-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b9af6dc

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
Name Type
@workflow/next Patch
workflow Patch
@workflow/world-testing Patch
@workflow/core Patch
@workflow/builders Patch
@workflow/cli Patch
@workflow/nitro Patch
@workflow/vitest Patch
@workflow/web-shared Patch
@workflow/web Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@vercel

vercel Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
example-nextjs-workflow-turbopack Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
example-nextjs-workflow-webpack Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
example-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-astro-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-express-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-fastify-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-hono-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-nestjs-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-nitro-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-nuxt-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-python-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-sveltekit-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-tanstack-start-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workbench-vite-workflow Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workflow-docs Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workflow-swc-playground Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workflow-tarballs Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC
workflow-web Ready Ready Preview, v0 Sep 25, 2026 4:05am UTC

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

❌ Some tests failed

❌ Failed E2E Tests

💻 Local Development (1 failed)

astro-stable-node (1 failed):

  • createHook({ experimental_force: true }) a run can take over its own earlier hook

⚠️ Flaky E2E Tests (passed on retry)

These tests failed at least once and passed on a retry. A recurring entry here is a real race worth investigating.

  • resume-or-start route pattern - resumeHook retried after start() reaches the new run (nextjs-webpack · local-dev / local / node / stable)

🛠 Infra Events (absorbed by the harness)

Platform anomalies the e2e harness detected and worked around (e.g. a run the queue never picked up, replaced by a fresh run). Clustered timestamps indicate a backend blip; a steady drip indicates a platform issue worth escalating.

  • cold-start-warmup · suite warmup (tanstack-start) · at 18:49:27Z · abandoned wrun_01M3CYCKRWEJ576S02BH11BM75
  • run-pickup-stall · hookCleanupTestWorkflow - hook token reuse after workflow completion (nextjs-webpack) · at 18:55:49Z · abandoned wrun_01M3CYRGC601XXXB0ZHN7TDYE1

E2E Test Summary

Summary
Passed Failed Skipped Total
❌ 💻 Local Development 4237 1 550 4788
✅ 📦 Local Production 4238 0 550 4788
✅ 🐘 Local Postgres 4238 0 550 4788
✅ 🪟 Windows 340 0 2 342
✅ vercel-http-transport 873 0 153 1026
✅ vercel-ws-transport 591 0 93 684
Total 14517 1 1898 16416
Details by Category

❌ 💻 Local Development

App Passed Failed Skipped
❌ astro-stable-node 141 1 29
✅ astro-stable-quickjs 142 0 29
✅ express-stable-node 142 0 29
✅ express-stable-quickjs 142 0 29
✅ fastify-stable-node 142 0 29
✅ fastify-stable-quickjs 142 0 29
✅ hono-stable-node 142 0 29
✅ hono-stable-quickjs 142 0 29
✅ nest-stable-node 142 0 29
✅ nest-stable-quickjs 142 0 29
✅ nextjs-turbopack-canary-node 170 0 1
✅ nextjs-turbopack-canary-quickjs 170 0 1
✅ nextjs-turbopack-stable-node 170 0 1
✅ nextjs-turbopack-stable-quickjs 170 0 1
✅ nextjs-webpack-canary-node 170 0 1
✅ nextjs-webpack-canary-quickjs 170 0 1
✅ nextjs-webpack-stable-node 170 0 1
✅ nextjs-webpack-stable-quickjs 170 0 1
✅ nitro-stable-node 142 0 29
✅ nitro-stable-quickjs 142 0 29
✅ nuxt-stable-node 142 0 29
✅ nuxt-stable-quickjs 142 0 29
✅ sveltekit-stable-node 161 0 10
✅ sveltekit-stable-quickjs 161 0 10
✅ tanstack-start-node 142 0 29
✅ tanstack-start-quickjs 142 0 29
✅ vite-stable-node 142 0 29
✅ vite-stable-quickjs 142 0 29

✅ 📦 Local Production

App Passed Failed Skipped
✅ astro-stable-node 142 0 29
✅ astro-stable-quickjs 142 0 29
✅ express-stable-node 142 0 29
✅ express-stable-quickjs 142 0 29
✅ fastify-stable-node 142 0 29
✅ fastify-stable-quickjs 142 0 29
✅ hono-stable-node 142 0 29
✅ hono-stable-quickjs 142 0 29
✅ nest-stable-node 142 0 29
✅ nest-stable-quickjs 142 0 29
✅ nextjs-turbopack-canary-node 170 0 1
✅ nextjs-turbopack-canary-quickjs 170 0 1
✅ nextjs-turbopack-stable-node 170 0 1
✅ nextjs-turbopack-stable-quickjs 170 0 1
✅ nextjs-webpack-canary-node 170 0 1
✅ nextjs-webpack-canary-quickjs 170 0 1
✅ nextjs-webpack-stable-node 170 0 1
✅ nextjs-webpack-stable-quickjs 170 0 1
✅ nitro-stable-node 142 0 29
✅ nitro-stable-quickjs 142 0 29
✅ nuxt-stable-node 142 0 29
✅ nuxt-stable-quickjs 142 0 29
✅ sveltekit-stable-node 161 0 10
✅ sveltekit-stable-quickjs 161 0 10
✅ tanstack-start-node 142 0 29
✅ tanstack-start-quickjs 142 0 29
✅ vite-stable-node 142 0 29
✅ vite-stable-quickjs 142 0 29

✅ 🐘 Local Postgres

App Passed Failed Skipped
✅ astro-stable-node 142 0 29
✅ astro-stable-quickjs 142 0 29
✅ express-stable-node 142 0 29
✅ express-stable-quickjs 142 0 29
✅ fastify-stable-node 142 0 29
✅ fastify-stable-quickjs 142 0 29
✅ hono-stable-node 142 0 29
✅ hono-stable-quickjs 142 0 29
✅ nest-stable-node 142 0 29
✅ nest-stable-quickjs 142 0 29
✅ nextjs-turbopack-canary-node 170 0 1
✅ nextjs-turbopack-canary-quickjs 170 0 1
✅ nextjs-turbopack-stable-node 170 0 1
✅ nextjs-turbopack-stable-quickjs 170 0 1
✅ nextjs-webpack-canary-node 170 0 1
✅ nextjs-webpack-canary-quickjs 170 0 1
✅ nextjs-webpack-stable-node 170 0 1
✅ nextjs-webpack-stable-quickjs 170 0 1
✅ nitro-stable-node 142 0 29
✅ nitro-stable-quickjs 142 0 29
✅ nuxt-stable-node 142 0 29
✅ nuxt-stable-quickjs 142 0 29
✅ sveltekit-stable-node 161 0 10
✅ sveltekit-stable-quickjs 161 0 10
✅ tanstack-start-node 142 0 29
✅ tanstack-start-quickjs 142 0 29
✅ vite-stable-node 142 0 29
✅ vite-stable-quickjs 142 0 29

✅ 🪟 Windows

App Passed Failed Skipped
✅ nextjs-turbopack-node 170 0 1
✅ nextjs-turbopack-quickjs 170 0 1

✅ vercel-http-transport

App Passed Failed Skipped
✅ example 141 0 30
✅ express 141 0 30
✅ hono 141 0 30
✅ nextjs-turbopack 168 0 3
✅ nitro 141 0 30
✅ vite 141 0 30

✅ vercel-ws-transport

App Passed Failed Skipped
✅ example 141 0 30
✅ express 141 0 30
✅ nextjs-turbopack 168 0 3
✅ vite 141 0 30

📋 View full workflow run

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

❌ The benchmark run for b9af6dc failed. See the run logs for details.

commit ead272e · Fri, 25 Sep 2026 04:27:09 GMT · run logs

Backend: vercel · app: nextjs-turbopack

Metric Scenario Best (ms) P75 (ms) P90 (ms) P99 (ms) Samples
TTFS step 188 (-87%) 💚 2190 🔴 (+20%) 🔻 2243 🔴 (+20%) 🔻 2754 🔴 (+38%) 🔻 30
TTFS stream 209 (-6.3%) 2211 🔴 (+6.5%) 2326 🔴 (+9.4%) 2604 🔴 (+13%) 30
TTFS hook + stream 2355 (+535%) 🔻 2512 🔴 (+25%) 🔻 2582 🔴 (+23%) 🔻 3070 🔴 (+32%) 🔻 30
Fan-out TTFS Promise.all(100 steps) 515 (+3.0%) 684 (-7.9%) 685 (-8.5%) 810 (-62%) 💚 10
Fan-out TTLS Promise.all(100 steps) 1820 (-14%) 3539 (-30%) 💚 5602 (-5.1%) 8292 (+3.9%) 10
STSO 1020 steps (inline) 97 (-18%) 💚 143 (-9.5%) 162 (-10%) 307 (-14%) 1019
WO 1020 steps 147198 (-6.2%) 147198 (-6.2%) 147198 (-6.2%) 147198 (-6.2%) 1
CRTT first chunk (pooled) 81 (+6.6%) 117 (-0.8%) 206 (+45%) 🔻 687 (+195%) 🔻 28

Streams

Scenario CRTT 1st p75 p90 p99 CDV max iters
paced control (100/s, 60B) 95 (-11%) 150 (-31%) 213 (-48%) 554 (-53%) 176 (-32%) 10
size sweep (100/s, 160B-12KB) 106 (-5%) 182 (-4%) 343 (+33%) 817 (+93%) 211 (+34%) 10
replay gateway-gpt-5.4-nano-2000t (1x) 140 (+24%) 137 (-28%) 182 (-29%) 450 (-25%) 423 (+30%) 3
replay eve-gpt-5.6-sol-2000t (1x) 104 (-11%) 134 (-26%) 164 (-29%) 300 (-24%) 239 (-34%) 2
replay eve-gpt-5.6-sol-2000t (2x) 85 (-27%) 179 (-25%) 227 (-27%) 575 (+16%) 368 (-1%) 3
ℹ️ Metric definitions & methodology

Streams: first-chunk RTT (the stream-open path, before any buffering/backpressure), CRTT percentiles, and worst delivery stall (CDV max). Cells are medians across iterations; per-run values in the artifacts. No 🔴/🟢 marks until targets attach.

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body) · Fan-out TTFS: fan-out time to first step (in-deployment start() → first of the parallel step bodies to complete) · Fan-out TTLS: fan-out time to last step (in-deployment start() → last of the parallel step bodies to complete, i.e. when the Promise.all resolves) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · CRTT: chunk round-trip time (per-chunk write → read latency, one clock domain: deployment → stream backend → same deployment) · CDV: chunk delay variation / delivery jitter (inter-arrival gap minus inter-write gap per seq-adjacent pair; skew-free; the row is each run's MAX positive value, so one stall moves it)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · Promise.all(100 steps): 100 trivial no-op steps started together in a single Promise.all; Fan-out TTFS is the first of them to complete and Fan-out TTLS the last, both from the in-deployment clientStart, so their gap is the spread the runtime adds across the fan-out · paced control (100/s, 60B): the control: 300 tiny (~60B) deltas metronome-paced at 100/s — zero workload structure, so it reads the transport floor and flush cadence, and disambiguates transport-wide vs workload-specific when a replay row moves · size sweep (100/s, 160B-12KB): same pacing as the control with deltas padded in rotation across seven log-spaced sizes (~160B–12KB) — rotation decouples size from stream position, so it isolates whether chunk size causes latency · replay gateway-gpt-5.4-nano-2000t (1x): raw provider SSE cadence captured at the AI gateway boundary (gpt-5.4-nano, the most popular gateway model; per-token deltas p50 208B = the modal production chunk size), replayed exactly as measured — the typical customer's workload; its CDV is the typical customer's real delivery jitter · replay eve-gpt-5.6-sol-2000t (1x): a captured eve turn (gpt-5.6-sol, the most-used demanding eve model; ~2000 output tokens = production p50 turn length) replayed exactly as measured — eve's envelope protocol re-ships the cumulative message so sizes ramp 142B→13KB; the demanding outlier tenant's reality · replay eve-gpt-5.6-sol-2000t (2x): the same eve capture at 2x — the headroom/stress row; real fast-tier models emit the same chunk sizes at proportionally higher rate, so time compression is a faithful speed model · first chunk (pooled): every run's seq-0 RTT pooled across all stream scenarios — the first chunk precedes any workload differentiation, so pooling samples one shared stream-open path with exact percentiles

Replay cadences (semantic sha256) — eve-gpt-5.6-sol-2000t eaf22f5946e7c61f3c65c7006d550df180cfabd4e706254a09f22aec0cfb420d · gateway-gpt-5.4-nano-2000t 6f24ac518b6b83ff1d0e85a5fe78230db192716d66a7fc6b2fe022752001d041

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600

All timestamps are deployment-side; runs are triggered in-deployment, so the CI runner and api.vercel.com sit outside every measured window. TTFS = start() → first step body (includes dispatch + any cold start); Fan-out TTFS/TTLS = first/last step completion of one Promise.all from the same anchor (the gap is the runtime’s fan-out spread); STSO/WO between step bodies; CRTT inside the workflow (excludes the api.vercel.com read path).

Cold starts stay in the numbers (real bursty-workload latency, inflates P75+); Best is the warm floor.

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor
Framework Flow route Step reg. Framework output
hono 265.3 KiB (±0) 96.0 KiB (±0) 1.93 MiB (±0)
nextjs-turbopack 272.8 KiB (±0) 426 B (±0) 922.5 KiB (+6 B)
About these numbers

Sizes are gzip; parentheses show the change against main.
Flow route and Step reg. gate this job, on raw bytes rather than the gzip shown, at max(2%, 50.0 KiB). Framework output is informational.

b9af6dc · run

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Sim World

Simulated world deterministic testing for races. Traces

🟠 world-sim scenario book — 1 fail of 42 total

fence=per-spec

scenario outcome events virt replay violations
✅ smoke-no-steps completed 3 0ms ok 0
✅ smoke-one-step completed 6 0ms ok 0
✅ hook-at-step-started completed 12 0ms ok 0
✅ hook-at-step-completed completed 12 0ms ok 0
✅ hook-at-hook-created completed 12 0ms ok 0
✅ deadline-hook-wins completed 7 1.0h ok 0
✅ deadline-expires completed 7 1.0h ok 0
✅ step-vs-timer-early-settlement completed 8 1.0h ok 0
✅ long-sleep completed 11 30.0d ok 0
✅ hook-never-arrives stalled 3 0ms skipped 0
✅ step-retries-twice completed 10 2.0s ok 0
✅ parallel-steps completed 9 0ms ok 0
✅ hook-on-execution-state completed 12 0ms ok 0
✅ peek-hook-before-branch completed 12 0ms ok 0
✅ peek-hook-after-branch completed 12 0ms ok 0
✅ peek-hook-at-registration completed 12 0ms ok 0
✅ race-hook-before-probe completed 12 0ms ok 0
✅ race-hook-after-probe completed 12 0ms ok 0
✅ race-duplicate-delivery completed 13 0ms ok 0
✅ attr-hook-before-step completed 11 0ms ok 0
✅ attr-hook-after-step completed 11 0ms ok 0
✅ attr-from-step-body completed 13 0ms ok 0
✅ fork-hook-after-timeout completed 14 1.0m ok 0
✅ fork-hook-before-timeout completed 14 1.0m ok 0
✅ count-hook-after-timeout completed 17 1.0m ok 0
✅ count-hook-before-timeout completed 20 1.0m ok 0
✅ stale-read-step-count-fork completed 20 1.0m ok 0
✅ stale-read-equal-step-counts completed 14 1.0m ok 0
✅ step-vs-step-fork completed 12 0ms ok 0
✅ step-vs-step-fork-fenced completed 12 0ms ok 0
✅ fence-catches-benign-direction completed 12 5ms ok 0
✅ in-flight-before-decision completed 17 1.0m ok 0
❌ in-flight-before-decision-counted completed 17 1.0m ok 0
✅ in-flight-after-decision completed 19 2.0m ok 0
✅ stale-read-step-count-fork-fenced completed 20 1.0m ok 0
✅ fork-hook-wins completed 13 1.0m ok 0
✅ fork-timeout-wins completed 13 1.0m ok 0
✅ unclaimed-payload-under-fork completed 17 1.0m ok 0
✅ claimed-payload-under-fork completed 17 1.0m ok 0
✅ writers-independent-step-bodies completed 12 0ms ok 0
✅ writers-scripted-tempo completed 12 0ms ok 0
✅ cancel-mid-step cancelled 7 0ms skipped 0

Full trace: world-sim.txt

@pranaygp
pranaygp disabled auto-merge September 25, 2026 18:44
@pranaygp
pranaygp merged commit 0547d9d into main Sep 25, 2026
44 of 76 checks passed
@pranaygp
pranaygp deleted the bump-next-dependency branch September 25, 2026 18:44
@github-actions

Copy link
Copy Markdown
Contributor

No backport to stable for 0547d9d (AI decision).

This is a routine patch bump of the pinned next devDependency and workbench app pins from 16.3.4 to 16.3.6, motivated by deduping the lockfile rather than by a vulnerability or a bug affecting stable. The consumer-facing next peerDependency range is unchanged, so stable users gain nothing from it.

To override, re-run the Backport to stable workflow manually via workflow_dispatch and paste this commit SHA into the ref input:

0547d9d890b7ede7aadfd28e8c64b0f32b23ce3e

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants