vercel/next.js · error · Error
Could not check for security updates. Please try again.
Error message
Could not check for security updates. Please try again.
What it means
readSecuritySnapshot combines GitHub advisories with npm registry data. When the GitHub advisory fetch already failed AND the fallback path (npm registry fetch or npm bulk advisories) also fails, there is no usable security data at all, so the tool throws this aggregate error whose `cause` array holds both underlying failures.
Solutions
- Restore network access to api.github.com and registry.npmjs.org, then retry the upgrade as the message suggests.
- Inspect `error.cause` (an array of the two underlying failures) to identify which provider failed and why (rate limit vs DNS vs HTTP).
- If rate-limited by GitHub, wait for the window to reset or provide an authenticated token.
- If behind a proxy/firewall, add allowlist entries for api.github.com and registry.npmjs.org.
Example fix
// before: CI blocks egress // after: allow required hosts in CI network policy allow: - api.github.com - registry.npmjs.org
Defensive patterns
Strategy: retry
Validate before calling
// pre-flight connectivity check
async function canReach(url: string) {
try { const r = await fetch(url, { method: 'HEAD' }); return r.ok || r.status < 500 }
catch { return false }
}
if (!(await canReach('https://registry.npmjs.org/next')) &&
!(await canReach('https://api.github.com/advisories?ecosystem=npm'))) {
throw new Error('No network access to advisory providers; fix connectivity first')
} Try / catch
try {
await upgrade()
} catch (e) {
if (e.message.includes('Please try again')) {
const [githubErr, npmErr] = e.cause ?? []
console.error('GitHub failed:', githubErr, 'npm failed:', npmErr)
// restore connectivity / wait out rate limits, then retry
} else throw e
} Prevention
- Allowlist api.github.com and registry.npmjs.org in CI firewalls before running upgrades.
- Avoid running security upgrades on fully offline machines.
- Inspect error.cause first — it names both underlying provider failures.
When it happens
Trigger: Running `next upgrade` while both api.github.com (rate limit / outage) and registry.npmjs.org (bulk advisory POST or packument GET) requests fail — e.g. fully offline, behind a blocking firewall/proxy, or both providers experiencing simultaneous incidents.
Common situations: CI machines with no internet egress; strict corporate firewalls blocking api.github.com and registry.npmjs.org; simultaneous GitHub and npm outages; DNS failures on locked-down hosts.
Related errors
- Could not check Next.js security advisories. Continuing…
- Could not determine the latest stable Next.js version.
- Could not prepare adoption documents for
- AI upgrades are not available for prerelease versions of…
- Could not determine the installed Next.js version.
AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20).
Data as JSON: /api/errors/62468d758d695f19.
Report an issue: GitHub.
Appendix: source
Thrown at packages/next/src/lib/upgrade/prepare-upgrade.ts:494
try {
const { value } = await fetchJSON(registryURL)
releases = parseReleases(value)
if (githubRanges) {
ranges = githubRanges
advisoryReference = ADVISORIES
} else {
// Query every published version, including prereleases: querying only the
// installed version could miss advisories affecting a candidate target.
const versions = Object.keys(
(value as { versions: Record<string, unknown> }).versions
).filter((version) => semver.valid(version))
ranges = affectedRanges(await readNpmAdvisories(versions))
advisoryReference = NPM_ADVISORIES
}
} catch (error) {
if (!githubRanges) {
throw new Error(
'Could not check for security updates. Please try again.',
{ cause: [githubFailure, error] }
)
}
throw error
}
return {
ranges,
releases,
references: [advisoryReference, registryURL],
}
}
function selectSecurityTarget(
source: string,
snapshot: SecuritySnapshotView on GitHub (pinned to 34433fd12e)