vercel/next.js · error · Error

The running Next.js version is not valid semver.

Error message

The running Next.js version is not valid semver.

What it means

getSecurityAdvisory (used for the startup security prompt) throws this when the passed running version string is not valid node-semver at all. Downstream code depends on semver.satisfies/major comparisons, so a non-semver version string is rejected up front instead of producing meaningless advisory checks.

Solutions

  1. Check `node -e "console.log(require('next/package.json').version)"` in the app and ensure it is a valid semver string like 15.3.2.
  2. Reinstall next from the npm registry (pnpm/npm install next) to restore a canonical version string.
  3. If using a fork or local build, ensure its package.json version is valid semver.
  4. Fix the caller to pass the resolved installed version, not a tag or placeholder.

Example fix

// before
await getSecurityAdvisory(process.env.NEXT_VERSION) // may be 'canary'
// after
const version = require('next/package.json').version
if (semver.valid(version)) await getSecurityAdvisory(version)
Defensive patterns

Strategy: validation

Validate before calling

import semver from 'semver'
const version = require('next/package.json').version
if (!semver.valid(version)) {
  throw new Error(`Installed next version "${version}" is not valid semver — reinstall next`)
}
await getSecurityAdvisory(version)

Type guard

function isValidVersion(version: string): boolean {
  return semver.valid(version) !== null
}

Try / catch

try {
  await getSecurityAdvisory(version)
} catch (error) {
  if ((error as Error).message.includes('not valid semver')) {
    console.error('Resolve the real installed version from next/package.json before checking advisories')
  }
  throw error
}

Prevention

When it happens

Trigger: Calling getSecurityAdvisory(version) where semver.valid(version) is null — e.g. version strings like "canary", "0.0.0-local", build-tampered strings, or values read from a customized next/package.json.

Common situations: Running a locally linked or patched next install whose package.json version was edited; monorepo aliasing to a source checkout; wrapper tooling passing process.env values instead of the real version.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20). Data as JSON: /api/errors/da3a45d83dbe6c4a. Report an issue: GitHub.

Appendix: source

Thrown at packages/next/src/lib/upgrade/prepare-upgrade.ts:326

    return null
  }

  // Patch releases remain available to explicit upgrades without a reminder.
  if (
    semver.major(release.version) === semver.major(version) &&
    semver.minor(release.version) === semver.minor(version)
  ) {
    return null
  }

  return release.version
}

// Count only advisories affecting the running version for the startup prompt.
// Full release selection remains in the explicit upgrade command.
export async function getSecurityAdvisory(version: string) {
  if (!semver.valid(version)) {
    throw new Error('The running Next.js version is not valid semver.')
  }

  if (semver.prerelease(version)) {
    return null
  }

  let advisories: Advisory[]
  let reference: string

  try {
    const result = await readGitHubAdvisories(version)
    advisories = result.advisories
    reference = result.reference
  } catch {
    advisories = await readNpmAdvisories([version])
    reference = NPM_ADVISORIES
  }

View on GitHub (pinned to 34433fd12e)