vercel/next.js · warning

Could not check Next.js security advisories. Continuing…

Error message

Could not check Next.js security advisories. Continuing without an upgrade assessment.

What it means

nudgeForSecurity checks the installed Next.js version against security advisories via getSecurityAdvisory (lazily required from prepare-upgrade). If that check throws (network error, malformed response), the command cannot assess security risk, logs this warning, and continues without an upgrade assessment (returns false) instead of failing the build.

Solutions

  1. Restore network access to the advisory endpoint (check proxy/firewall/DNS) and re-run.
  2. Retry later if the advisory service is down or rate-limiting; the build proceeds either way.
  3. Manually review current Next.js security advisories and upgrade if your version is affected.
Defensive patterns

Strategy: fallback

Validate before calling

// Verify egress to the advisory endpoint before builds in restricted envs
curl -fsS --max-time 5 https://nextjs.org -o /dev/null && echo network-ok || echo offline

Try / catch

try {
  await nextBuild()
} catch (e) {
  // advisory-check failure is a warning, not fatal; handle only real build errors
  throw e
}
// To silence network dependence entirely, ensure the environment allows egress or pin a known-safe version.

Prevention

When it happens

Trigger: Any command that triggers nudgeForSecurity while the advisory fetch fails: no network access, DNS/proxy failures, rate limiting, or an unexpected API response from the advisory source.

Common situations: Building in CI or offline environments with restricted egress; corporate proxies blocking the advisory endpoint; transient API outages.

Related errors


AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20). Data as JSON: /api/errors/240e173fd303ff21. Report an issue: GitHub.

Appendix: source

Thrown at packages/next/src/lib/upgrade/nudge.ts:171

async function nudgeForSecurity(
  options: SecurityNudgeOptions,
  policy: 'security' | 'latest' | 'future'
): Promise<boolean> {
  let advisory
  const version = process.env.__NEXT_VERSION || 'unknown'

  try {
    if (!(await getAgentName())) {
      return false
    }

    // Reuse upgrade's advisory readers only after detecting an agent.
    const { getSecurityAdvisory } =
      require('./prepare-upgrade') as typeof import('./prepare-upgrade')
    advisory = await getSecurityAdvisory(version)
  } catch {
    Log.warn(
      'Could not check Next.js security advisories. Continuing without an upgrade assessment.'
    )
    return false
  }

  if (!advisory) {
    return false
  }

  const { reference } = advisory
  await showNudge(
    options,
    version,
    'security',
    `Your version of Next.js is affected by a published security advisory and can be automatically upgraded.

**We strongly recommend you upgrade Next.js.**

View on GitHub (pinned to 34433fd12e)