{"record":{"id":"240e173fd303ff21","repo":"vercel/next.js","slug":"could-not-check-next-js-security-advisories-continuing","errorCode":null,"errorMessage":"Could not check Next.js security advisories. Continuing without an upgrade assessment.","messagePattern":"Could not check Next\\.js security advisories\\. Continuing without an upgrade assessment\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"packages/next/src/lib/upgrade/nudge.ts","lineNumber":171,"sourceCode":"\nasync function nudgeForSecurity(\n  options: SecurityNudgeOptions,\n  policy: 'security' | 'latest' | 'future'\n): Promise<boolean> {\n  let advisory\n  const version = process.env.__NEXT_VERSION || 'unknown'\n\n  try {\n    if (!(await getAgentName())) {\n      return false\n    }\n\n    // Reuse upgrade's advisory readers only after detecting an agent.\n    const { getSecurityAdvisory } =\n      require('./prepare-upgrade') as typeof import('./prepare-upgrade')\n    advisory = await getSecurityAdvisory(version)\n  } catch {\n    Log.warn(\n      'Could not check Next.js security advisories. Continuing without an upgrade assessment.'\n    )\n    return false\n  }\n\n  if (!advisory) {\n    return false\n  }\n\n  const { reference } = advisory\n  await showNudge(\n    options,\n    version,\n    'security',\n    `Your version of Next.js is affected by a published security advisory and can be automatically upgraded.\n\n**We strongly recommend you upgrade Next.js.**\n","sourceCodeStart":153,"sourceCodeEnd":189,"githubUrl":"https://github.com/vercel/next.js/blob/34433fd12ee8074ea3f47af9f36255c7390d0301/packages/next/src/lib/upgrade/nudge.ts#L153-L189","documentation":"nudgeForSecurity checks the installed Next.js version against security advisories via getSecurityAdvisory (lazily required from prepare-upgrade). If that check throws (network error, malformed response), the command cannot assess security risk, logs this warning, and continues without an upgrade assessment (returns false) instead of failing the build.","triggerScenarios":"Any command that triggers nudgeForSecurity while the advisory fetch fails: no network access, DNS/proxy failures, rate limiting, or an unexpected API response from the advisory source.","commonSituations":"Building in CI or offline environments with restricted egress; corporate proxies blocking the advisory endpoint; transient API outages.","solutions":["Restore network access to the advisory endpoint (check proxy/firewall/DNS) and re-run.","Retry later if the advisory service is down or rate-limiting; the build proceeds either way.","Manually review current Next.js security advisories and upgrade if your version is affected."],"exampleFix":null,"handlingStrategy":"fallback","validationCode":"// Verify egress to the advisory endpoint before builds in restricted envs\ncurl -fsS --max-time 5 https://nextjs.org -o /dev/null && echo network-ok || echo offline","typeGuard":null,"tryCatchPattern":"try {\n  await nextBuild()\n} catch (e) {\n  // advisory-check failure is a warning, not fatal; handle only real build errors\n  throw e\n}\n// To silence network dependence entirely, ensure the environment allows egress or pin a known-safe version.","preventionTips":["Allow egress to Next.js endpoints in CI proxies/firewalls.","Pin to patched versions promptly so advisory checks are moot.","Treat the warning as a prompt to manually review advisories in offline environments.","Retry builds after transient network outages."],"tags":["network","security","upgrade","nextjs"],"backgroundTag":"network-request-failed","analyzedSha":"34433fd12ee8074ea3f47af9f36255c7390d0301","analyzedAt":"2026-09-20T18:20:20.576Z","contentChangedAt":"2026-09-20T18:20:20.576Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}