{"record":{"id":"8e58f83ddb8b776a","repo":"vercel/next.js","slug":"could-not-check-for-security-updates","errorCode":null,"errorMessage":"Could not check for security updates.","messagePattern":"Could not check for security updates\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/next/src/lib/upgrade/prepare-upgrade.ts","lineNumber":249,"sourceCode":"\n    if (metadata.version !== version) {\n      throw new Error('Could not determine a safe Next.js version.')\n    }\n\n    return [{ version }]\n  })\n}\n\nfunction affectedRanges(advisories: Advisory[]): string[] {\n  const ranges: string[] = []\n\n  for (const advisory of advisories) {\n    if (\n      !advisory ||\n      !Array.isArray(advisory.vulnerabilities) ||\n      !('withdrawn_at' in advisory)\n    ) {\n      throw new Error('Could not check for security updates.')\n    }\n\n    if (advisory.withdrawn_at) {\n      continue\n    }\n\n    for (const finding of advisory.vulnerabilities) {\n      if (\n        !finding.package ||\n        typeof finding.package.name !== 'string' ||\n        typeof finding.package.ecosystem !== 'string'\n      ) {\n        throw new Error('Could not check for security updates.')\n      }\n\n      if (\n        finding.package.ecosystem !== 'npm' ||\n        finding.package.name !== 'next'","sourceCodeStart":231,"sourceCodeEnd":267,"githubUrl":"https://github.com/vercel/next.js/blob/34433fd12ee8074ea3f47af9f36255c7390d0301/packages/next/src/lib/upgrade/prepare-upgrade.ts#L231-L267","documentation":"affectedRanges validates each advisory object from GitHub before extracting vulnerable ranges and throws this when an advisory is not the expected shape: missing/falsy object, `vulnerabilities` not an array, or `withdrawn_at` key absent. GitHub's advisory schema is trusted only after these checks; anything else aborts the security check rather than producing a wrong 'safe' verdict.","triggerScenarios":"readGitHubAdvisories() or readNpmAdvisories() output fed to affectedRanges where an element is null, lacks a vulnerabilities array, or has no withdrawn_at field — e.g. a GitHub API schema change, a proxy injecting a different payload, or an npm bulk endpoint item shape change.","commonSituations":"GitHub advisories API returning an unexpected envelope; mirror/CDN rewriting responses; npm's bulk advisory endpoint changing its item format; version skew where the tooling expects a newer/older schema.","solutions":["Retry — if caused by a transient bad response, a repeat may succeed.","Inspect the raw response from https://api.github.com/advisories?ecosystem=npm&affects=next&type=reviewed to see the actual shape.","Update the Next.js tooling if the GitHub/npm advisory schema changed.","Remove any proxy or interceptor that rewrites API responses."],"exampleFix":"// before\nconst advisories = await res.json()\naffectedRanges(advisories) // throws on shape mismatch\n// after\nconst advisories = await res.json()\nif (!Array.isArray(advisories)) throw new Error('bad advisories payload')\naffectedRanges(advisories.filter(a => a && Array.isArray(a.vulnerabilities)))","handlingStrategy":"type-guard","validationCode":"const res = await fetch('https://api.github.com/advisories?ecosystem=npm&affects=next&type=reviewed')\nconst advisories = await res.json()\nif (!Array.isArray(advisories) || advisories.some(a => !a || !Array.isArray(a.vulnerabilities) || !('withdrawn_at' in a))) {\n  throw new Error('GitHub advisories payload has unexpected shape')\n}","typeGuard":"function isAdvisory(value: unknown): value is Advisory {\n  return typeof value === 'object' && value !== null\n    && Array.isArray((value as any).vulnerabilities)\n    && 'withdrawn_at' in value\n}","tryCatchPattern":"try {\n  const ref = await getSecurityAdvisory(version)\n} catch (error) {\n  if ((error as Error).message === 'Could not check for security updates.') {\n    // advisory schema mismatch — check GitHub API changelog / pin tooling version\n  }\n  throw error\n}","preventionTips":["Keep the Next.js tooling updated when GitHub or npm change advisory schemas","Don't route api.github.com through rewriting proxies","Validate advisory payloads yourself in wrapper scripts before trusting 'safe' verdicts"],"tags":["security","schema-validation","api","github"],"backgroundTag":"schema-validation-failed","analyzedSha":"34433fd12ee8074ea3f47af9f36255c7390d0301","analyzedAt":"2026-09-20T18:20:20.576Z","contentChangedAt":"2026-09-20T18:20:20.576Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}