vercel/next.js · error · Error

Could not check for security updates. Please try again.

Error message

Could not check for security updates. Please try again.

What it means

readSecuritySnapshot combines GitHub advisories with npm registry data. When the GitHub advisory fetch already failed AND the fallback path (npm registry fetch or npm bulk advisories) also fails, there is no usable security data at all, so the tool throws this aggregate error whose `cause` array holds both underlying failures.

Solutions

  1. Restore network access to api.github.com and registry.npmjs.org, then retry the upgrade as the message suggests.
  2. Inspect `error.cause` (an array of the two underlying failures) to identify which provider failed and why (rate limit vs DNS vs HTTP).
  3. If rate-limited by GitHub, wait for the window to reset or provide an authenticated token.
  4. If behind a proxy/firewall, add allowlist entries for api.github.com and registry.npmjs.org.

Example fix

// before: CI blocks egress
// after: allow required hosts in CI network policy
allow:
  - api.github.com
  - registry.npmjs.org
Defensive patterns

Strategy: retry

Validate before calling

// pre-flight connectivity check
async function canReach(url: string) {
  try { const r = await fetch(url, { method: 'HEAD' }); return r.ok || r.status < 500 }
  catch { return false }
}
if (!(await canReach('https://registry.npmjs.org/next')) &&
    !(await canReach('https://api.github.com/advisories?ecosystem=npm'))) {
  throw new Error('No network access to advisory providers; fix connectivity first')
}

Try / catch

try {
  await upgrade()
} catch (e) {
  if (e.message.includes('Please try again')) {
    const [githubErr, npmErr] = e.cause ?? []
    console.error('GitHub failed:', githubErr, 'npm failed:', npmErr)
    // restore connectivity / wait out rate limits, then retry
  } else throw e
}

Prevention

When it happens

Trigger: Running `next upgrade` while both api.github.com (rate limit / outage) and registry.npmjs.org (bulk advisory POST or packument GET) requests fail — e.g. fully offline, behind a blocking firewall/proxy, or both providers experiencing simultaneous incidents.

Common situations: CI machines with no internet egress; strict corporate firewalls blocking api.github.com and registry.npmjs.org; simultaneous GitHub and npm outages; DNS failures on locked-down hosts.

Related errors


AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20). Data as JSON: /api/errors/62468d758d695f19. Report an issue: GitHub.

Appendix: source

Thrown at packages/next/src/lib/upgrade/prepare-upgrade.ts:494

  try {
    const { value } = await fetchJSON(registryURL)
    releases = parseReleases(value)

    if (githubRanges) {
      ranges = githubRanges
      advisoryReference = ADVISORIES
    } else {
      // Query every published version, including prereleases: querying only the
      // installed version could miss advisories affecting a candidate target.
      const versions = Object.keys(
        (value as { versions: Record<string, unknown> }).versions
      ).filter((version) => semver.valid(version))
      ranges = affectedRanges(await readNpmAdvisories(versions))
      advisoryReference = NPM_ADVISORIES
    }
  } catch (error) {
    if (!githubRanges) {
      throw new Error(
        'Could not check for security updates. Please try again.',
        { cause: [githubFailure, error] }
      )
    }

    throw error
  }

  return {
    ranges,
    releases,
    references: [advisoryReference, registryURL],
  }
}

function selectSecurityTarget(
  source: string,
  snapshot: SecuritySnapshot

View on GitHub (pinned to 34433fd12e)