{"record":{"id":"62468d758d695f19","repo":"vercel/next.js","slug":"could-not-check-for-security-updates-please-try-again","errorCode":null,"errorMessage":"Could not check for security updates. Please try again.","messagePattern":"Could not check for security updates\\. Please try again\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/next/src/lib/upgrade/prepare-upgrade.ts","lineNumber":494,"sourceCode":"  try {\n    const { value } = await fetchJSON(registryURL)\n    releases = parseReleases(value)\n\n    if (githubRanges) {\n      ranges = githubRanges\n      advisoryReference = ADVISORIES\n    } else {\n      // Query every published version, including prereleases: querying only the\n      // installed version could miss advisories affecting a candidate target.\n      const versions = Object.keys(\n        (value as { versions: Record<string, unknown> }).versions\n      ).filter((version) => semver.valid(version))\n      ranges = affectedRanges(await readNpmAdvisories(versions))\n      advisoryReference = NPM_ADVISORIES\n    }\n  } catch (error) {\n    if (!githubRanges) {\n      throw new Error(\n        'Could not check for security updates. Please try again.',\n        { cause: [githubFailure, error] }\n      )\n    }\n\n    throw error\n  }\n\n  return {\n    ranges,\n    releases,\n    references: [advisoryReference, registryURL],\n  }\n}\n\nfunction selectSecurityTarget(\n  source: string,\n  snapshot: SecuritySnapshot","sourceCodeStart":476,"sourceCodeEnd":512,"githubUrl":"https://github.com/vercel/next.js/blob/34433fd12ee8074ea3f47af9f36255c7390d0301/packages/next/src/lib/upgrade/prepare-upgrade.ts#L476-L512","documentation":"readSecuritySnapshot combines GitHub advisories with npm registry data. When the GitHub advisory fetch already failed AND the fallback path (npm registry fetch or npm bulk advisories) also fails, there is no usable security data at all, so the tool throws this aggregate error whose `cause` array holds both underlying failures.","triggerScenarios":"Running `next upgrade` while both api.github.com (rate limit / outage) and registry.npmjs.org (bulk advisory POST or packument GET) requests fail — e.g. fully offline, behind a blocking firewall/proxy, or both providers experiencing simultaneous incidents.","commonSituations":"CI machines with no internet egress; strict corporate firewalls blocking api.github.com and registry.npmjs.org; simultaneous GitHub and npm outages; DNS failures on locked-down hosts.","solutions":["Restore network access to api.github.com and registry.npmjs.org, then retry the upgrade as the message suggests.","Inspect `error.cause` (an array of the two underlying failures) to identify which provider failed and why (rate limit vs DNS vs HTTP).","If rate-limited by GitHub, wait for the window to reset or provide an authenticated token.","If behind a proxy/firewall, add allowlist entries for api.github.com and registry.npmjs.org."],"exampleFix":"// before: CI blocks egress\n// after: allow required hosts in CI network policy\nallow:\n  - api.github.com\n  - registry.npmjs.org","handlingStrategy":"retry","validationCode":"// pre-flight connectivity check\nasync function canReach(url: string) {\n  try { const r = await fetch(url, { method: 'HEAD' }); return r.ok || r.status < 500 }\n  catch { return false }\n}\nif (!(await canReach('https://registry.npmjs.org/next')) &&\n    !(await canReach('https://api.github.com/advisories?ecosystem=npm'))) {\n  throw new Error('No network access to advisory providers; fix connectivity first')\n}","typeGuard":null,"tryCatchPattern":"try {\n  await upgrade()\n} catch (e) {\n  if (e.message.includes('Please try again')) {\n    const [githubErr, npmErr] = e.cause ?? []\n    console.error('GitHub failed:', githubErr, 'npm failed:', npmErr)\n    // restore connectivity / wait out rate limits, then retry\n  } else throw e\n}","preventionTips":["Allowlist api.github.com and registry.npmjs.org in CI firewalls before running upgrades.","Avoid running security upgrades on fully offline machines.","Inspect error.cause first — it names both underlying provider failures."],"tags":["network","security-advisories","offline","upgrade"],"backgroundTag":"network-request-failed","analyzedSha":"34433fd12ee8074ea3f47af9f36255c7390d0301","analyzedAt":"2026-09-20T18:20:20.576Z","contentChangedAt":"2026-09-20T18:20:20.576Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}