{"record":{"id":"da3a45d83dbe6c4a","repo":"vercel/next.js","slug":"the-running-next-js-version-is-not-valid-semver","errorCode":null,"errorMessage":"The running Next.js version is not valid semver.","messagePattern":"The running Next\\.js version is not valid semver\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/next/src/lib/upgrade/prepare-upgrade.ts","lineNumber":326,"sourceCode":"    return null\n  }\n\n  // Patch releases remain available to explicit upgrades without a reminder.\n  if (\n    semver.major(release.version) === semver.major(version) &&\n    semver.minor(release.version) === semver.minor(version)\n  ) {\n    return null\n  }\n\n  return release.version\n}\n\n// Count only advisories affecting the running version for the startup prompt.\n// Full release selection remains in the explicit upgrade command.\nexport async function getSecurityAdvisory(version: string) {\n  if (!semver.valid(version)) {\n    throw new Error('The running Next.js version is not valid semver.')\n  }\n\n  if (semver.prerelease(version)) {\n    return null\n  }\n\n  let advisories: Advisory[]\n  let reference: string\n\n  try {\n    const result = await readGitHubAdvisories(version)\n    advisories = result.advisories\n    reference = result.reference\n  } catch {\n    advisories = await readNpmAdvisories([version])\n    reference = NPM_ADVISORIES\n  }\n","sourceCodeStart":308,"sourceCodeEnd":344,"githubUrl":"https://github.com/vercel/next.js/blob/34433fd12ee8074ea3f47af9f36255c7390d0301/packages/next/src/lib/upgrade/prepare-upgrade.ts#L308-L344","documentation":"getSecurityAdvisory (used for the startup security prompt) throws this when the passed running version string is not valid node-semver at all. Downstream code depends on semver.satisfies/major comparisons, so a non-semver version string is rejected up front instead of producing meaningless advisory checks.","triggerScenarios":"Calling getSecurityAdvisory(version) where semver.valid(version) is null — e.g. version strings like \"canary\", \"0.0.0-local\", build-tampered strings, or values read from a customized next/package.json.","commonSituations":"Running a locally linked or patched next install whose package.json version was edited; monorepo aliasing to a source checkout; wrapper tooling passing process.env values instead of the real version.","solutions":["Check `node -e \"console.log(require('next/package.json').version)\"` in the app and ensure it is a valid semver string like 15.3.2.","Reinstall next from the npm registry (pnpm/npm install next) to restore a canonical version string.","If using a fork or local build, ensure its package.json version is valid semver.","Fix the caller to pass the resolved installed version, not a tag or placeholder."],"exampleFix":"// before\nawait getSecurityAdvisory(process.env.NEXT_VERSION) // may be 'canary'\n// after\nconst version = require('next/package.json').version\nif (semver.valid(version)) await getSecurityAdvisory(version)","handlingStrategy":"validation","validationCode":"import semver from 'semver'\nconst version = require('next/package.json').version\nif (!semver.valid(version)) {\n  throw new Error(`Installed next version \"${version}\" is not valid semver — reinstall next`)\n}\nawait getSecurityAdvisory(version)","typeGuard":"function isValidVersion(version: string): boolean {\n  return semver.valid(version) !== null\n}","tryCatchPattern":"try {\n  await getSecurityAdvisory(version)\n} catch (error) {\n  if ((error as Error).message.includes('not valid semver')) {\n    console.error('Resolve the real installed version from next/package.json before checking advisories')\n  }\n  throw error\n}","preventionTips":["Always read the version from next/package.json, not env vars or tags","Reinstall next if its package.json version was hand-edited (common with forks/local patches)","Validate version strings with semver.valid before passing to any upgrade API"],"tags":["semver","versioning","validation"],"backgroundTag":"invalid-argument-value","analyzedSha":"34433fd12ee8074ea3f47af9f36255c7390d0301","analyzedAt":"2026-09-20T18:20:20.576Z","contentChangedAt":"2026-09-20T18:20:20.576Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}