vercel/next.js · error · Error
The running Next.js version is not valid semver.
Error message
The running Next.js version is not valid semver.
What it means
getSecurityAdvisory (used for the startup security prompt) throws this when the passed running version string is not valid node-semver at all. Downstream code depends on semver.satisfies/major comparisons, so a non-semver version string is rejected up front instead of producing meaningless advisory checks.
Solutions
- Check `node -e "console.log(require('next/package.json').version)"` in the app and ensure it is a valid semver string like 15.3.2.
- Reinstall next from the npm registry (pnpm/npm install next) to restore a canonical version string.
- If using a fork or local build, ensure its package.json version is valid semver.
- Fix the caller to pass the resolved installed version, not a tag or placeholder.
Example fix
// before
await getSecurityAdvisory(process.env.NEXT_VERSION) // may be 'canary'
// after
const version = require('next/package.json').version
if (semver.valid(version)) await getSecurityAdvisory(version) Defensive patterns
Strategy: validation
Validate before calling
import semver from 'semver'
const version = require('next/package.json').version
if (!semver.valid(version)) {
throw new Error(`Installed next version "${version}" is not valid semver — reinstall next`)
}
await getSecurityAdvisory(version) Type guard
function isValidVersion(version: string): boolean {
return semver.valid(version) !== null
} Try / catch
try {
await getSecurityAdvisory(version)
} catch (error) {
if ((error as Error).message.includes('not valid semver')) {
console.error('Resolve the real installed version from next/package.json before checking advisories')
}
throw error
} Prevention
- Always read the version from next/package.json, not env vars or tags
- Reinstall next if its package.json version was hand-edited (common with forks/local patches)
- Validate version strings with semver.valid before passing to any upgrade API
When it happens
Trigger: Calling getSecurityAdvisory(version) where semver.valid(version) is null — e.g. version strings like "canary", "0.0.0-local", build-tampered strings, or values read from a customized next/package.json.
Common situations: Running a locally linked or patched next install whose package.json version was edited; monorepo aliasing to a source checkout; wrapper tooling passing process.env values instead of the real version.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- Next.js is affected by an active advisory.
- No safe Next.js update is currently available.
- Could not determine a safe Next.js version.
- Could not determine the installed Next.js version.
- mixed-type fixed key block claims a
AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20).
Data as JSON: /api/errors/da3a45d83dbe6c4a.
Report an issue: GitHub.
Appendix: source
Thrown at packages/next/src/lib/upgrade/prepare-upgrade.ts:326
return null
}
// Patch releases remain available to explicit upgrades without a reminder.
if (
semver.major(release.version) === semver.major(version) &&
semver.minor(release.version) === semver.minor(version)
) {
return null
}
return release.version
}
// Count only advisories affecting the running version for the startup prompt.
// Full release selection remains in the explicit upgrade command.
export async function getSecurityAdvisory(version: string) {
if (!semver.valid(version)) {
throw new Error('The running Next.js version is not valid semver.')
}
if (semver.prerelease(version)) {
return null
}
let advisories: Advisory[]
let reference: string
try {
const result = await readGitHubAdvisories(version)
advisories = result.advisories
reference = result.reference
} catch {
advisories = await readNpmAdvisories([version])
reference = NPM_ADVISORIES
}
View on GitHub (pinned to 34433fd12e)