Reposted by JoshNext.js @nextjs.org · 03/08/2026Next.js 16.3 is now available! • Up to 90% less memory in dev • Faster builds, type checking, and rendering • Better tooling for AI agents • Custom error boundaries • Instant Navigations for SPA-like responsiveness nextjs.org/blog/next-16-3 Here's what's new ↓ 4767
Reposted by JoshAurora Scharff @aurorascharff.no · 22/07/2026Building SPA-like experiences with Next.js (3) With Partial Prefetching, you can tap a link and the page arrives with its content already there. Live demo, source code, and docs below ↓ 2352
Reposted by JoshVercel @vercel.com · 17/06/2026Introducing eve, an agent framework. 𝚊𝚐𝚎𝚗𝚝/ 𝚊𝚐𝚎𝚗𝚝.𝚝𝚜 𝚒𝚗𝚜𝚝𝚛𝚞𝚌𝚝𝚒𝚘𝚗𝚜.𝚖𝚍 𝚝𝚘𝚘𝚕𝚜/ 𝚜𝚔𝚒𝚕𝚕𝚜/ 𝚜𝚊𝚗𝚍𝚋𝚘𝚡/ 𝚜𝚌𝚑𝚎𝚍𝚞𝚕𝚎𝚜/ Like Next.js, for agents. vercel.com/blog/introd...vercel.comIntroducing eveIntroducing eve, the open-source agent framework from Vercel for building, running, and scaling agents in production, with durable execution, sandboxed compute, approvals, channels, tracing, and evals built in. 182
Reposted by JoshNext.js @nextjs.org · 20/03/2026Next.js 16.2: AI Improvements • Next.js-aware browser lets Agents improve your app • 𝙰𝙶𝙴𝙽𝚃𝚂.𝚖𝚍 included in 𝚌𝚛𝚎𝚊𝚝𝚎-𝚗𝚎𝚡𝚝-𝚊𝚙𝚙 by default • Browser errors forwarded to terminal • Dev server lock file prevents duplicate servers nextjs.org/blog/next-1...nextjs.orgNext.js 16.2: AI ImprovementsNext.js 16.2 ships AGENTS.md in create-next-app, browser log forwarding, dev server lock file with PID, and next-browser for AI agent debugging. 1153
Reposted by JoshNext.js @nextjs.org · 26/03/2026Next.js is used by millions of developers across every major cloud. Making it work well everywhere is on us. Here's what we've built with Netlify, Cloudflare, OpenNext, AWS, and Google Cloud, and the commitments we're making. nextjs.org/nextjs-acro...nextjs.orgNext.js Across Platforms: Adapters, OpenNext, and Our CommitmentsNext.js 16.2 introduces a stable Adapter API, a public adapter test suite, and a working group for more consistent deployment across platforms. 0498
Reposted by JoshVercel @vercel.com · 19/12/2025We paid $1 million to hackers to harden our firewall defenses. Today we're telling the story of how we strengthened our WAF, disclosing a runtime mitigation layer for the first time, and how we partnered with @Hacker0x01 to defend against React2Shell. vercel.com/blog/our-mi...vercel.comOur $1 million hacker challenge for React2Shell - VercelWe paid $1M to security researchers to break our WAF. Here's what we learned defending against React2Shell. 1113
Reposted by JoshDaishi Kato @daishikato.com · 04/12/2025⛩️ Waku v0.27.3 has been released. - Dependency updates addressing the critical React Server Components security vulnerability - Various small improvements All users should update immediately: github.com/wakujs/waku/...github.comUpdate instructions for CVE-2025-55182 · wakujs waku · Discussion #1823References https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components https://www.facebook.com/security/advisories/cve-2025-55182 GHSA-fv66-9v8q-g76r Affected vers... 0215
Josh @storyhb.com · 03/12/2025At some point in the future we will share details. For now we are withholding to allow the industry to protect themselves given the severity of the vulnerability 180
Reposted by JoshNext.js @nextjs.org · 03/12/2025A critical vulnerability in React Server Components (CVE-2025-55182) affects React 19 and frameworks, including Next.js (CVE-2025-66478). All users should upgrade to the latest patched version in their release line. nextjs.org/blog/CVE-20...nextjs.orgSecurity Advisory: CVE-2025-66478A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately. 22612
Reposted by JoshDeno @deno.land · 03/12/2025Our thanks to the @react.dev team for informing us so that we could provide mitigation for our users. bsky.app/profile/deno... 0171
Reposted by JoshNetlify @netlify.com · 03/12/2025Thank you to the React and Next.js teams for involving us early and for the clear communication. We were able to patch our network ahead of disclosure to help keep our customers secure. bsky.app/profile/netl... 0171
Reposted by JoshReact @react.dev · 03/12/2025There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12...react.devCritical Security Vulnerability in React Server Components – ReactThe library for web and native user interfaces 714691
Josh @storyhb.com · 26/11/2025Basically make dynamic things as lazy as possible. Unwrapping them deeply where you likely have a good fallback UI that isn’t super generic and super high up 300
Josh @storyhb.com · 26/11/2025You can serialize a promise to a client component without awaiting it on the server. So you can pass the pending logged in value into a context provider and then `use` it deeply on the client with Suspense around wherever it is read 130
Josh @storyhb.com · 23/10/2025Even for high cardinality and user specific data we recommend passing the param or cookie or other runtime value into the “use cache” function as an argument. But sometimes that’s just not how a project is set up so you can opt into allowing these runtime values “on the inside” of a use cache… 120
Josh @storyhb.com · 23/10/2025… never read back from it. Use cache private is sort of a different consideration. This is more about how you have your data fetching code factored. You might have a common data fetching utility that reads cookies internally. Because of this you can’t use it inside the other “use cache” types 110
Josh @storyhb.com · 23/10/2025Since this data isn’t going to be pre-rendered into a static shell you might want to make renders faster by server caching it in which case “use cache: remote” can make sense. But you should consider if the data will even have a decent cache utilization rate. No point in writing to a cache if you… 110
Josh @storyhb.com · 23/10/2025We are also looking at how we can support server caching in a way that is both local (latency free) and cheap (ideally cost free or on the order of how much you revalidate rather than read). It’s a hard problem but we’re very interested in solving it 020
Josh @storyhb.com · 23/10/2025… bigger role in future features where tags on the client allow very fine grained refetching. 110
Josh @storyhb.com · 23/10/2025At the moment we don’t server cache the default “use cache” on Vercel. So if a Cache Function is encountered outside of static pre-rendering it will be forgotten on the server. But again it’s still providing important information to the client router in some circumstances and will play a… 120
Josh @storyhb.com · 23/10/2025Also to be clear by default self hosted next doesn’t actually remotely store cache entries. You have to plug it into some service. Of course hosts for Next.js like Vercel can provide one for you as part of their integration with next 110
Josh @storyhb.com · 23/10/2025Part of this feature rollout that is hard is we have `unstable_cache` which is just a server caching API. And it’s so easy to assume that “use cache” is this API stabilized. But really it’s like “use cache” is entirely new and the storage engine for “…: remote” is the `unstable_cache` replacement 100
Josh @storyhb.com · 23/10/2025Also maybe you never revalidate by path. It’s a convenient API but it will over revalidate because it doesn’t target specific data updates 010
Josh @storyhb.com · 23/10/2025Forbidding cacheTag is good but you also need to consider revalidatePath. It’s unfortunate but every cache is implicitly tagged with the path of the segment it’s read from. You could sort of define your own semantics here though and say that a revalidatePath doesn’t expire these cache entries 200
Josh @storyhb.com · 23/10/2025But for teams that have solved this for ISR the same techniques can generally work for the use cache entries 010
Josh @storyhb.com · 23/10/2025… system coordinate. Since the cache information is powering ISR and prefetching in the client the high cardinality entries may not be worth also server caching (i.e. in redis) nor in local memory (because tag invalidation is hard) 210
Josh @storyhb.com · 23/10/2025Yup! If you self host you already have to manage this for ISR if you run more than one process. so the same kind of tag management is required for cache handlers. You can accomplish this by having a forgetful default cache (memory size zero) or by going remote and letting some other… 100
Josh @storyhb.com · 23/10/2025But we need to balance what is possible with what the framework nudges you towards. If it were trivial to make blocking routes most Next.js apps would be slow by default. We want the inverse. It’s fast by default but if you know you have a super fast backend or you care more about a single complete… 110
Josh @storyhb.com · 23/10/2025Yeah I think there is maybe an analog for the idea of opting into runtime prefetching. Maybe you want to opt into runtime “initial load”. This can’t ever be instant because we need the request data but if you express an intent to allow for this maybe that is the way to say… 110
Josh @storyhb.com · 23/10/2025We are still missing features that make client data fetching attractive like better pagination support and lazy loading UI that is not part of the initial page view or live updates. We are going to tackle of these cases soon 120
Josh @storyhb.com · 23/10/2025Client data fetching can’t be cached with “use cache” and many data fetching libraries on the client don’t suspend so to maximally take advantage of these capabilities moving data fetching to the server is an important step. But I don’t want to suggest client data fetching must never be done 100
Josh @storyhb.com · 23/10/2025Well it sounds like Tom will like to try out the runtime prefetching stuff we are working on. We will of course follow up on the HMR bug. We are going to need users to try this feature out and we will find out where there are rough edges 100
Reposted by Joshdan @danabra.mov · 23/10/2025very good talk by @samselikoff.com about App Router instant navigations and "use cache", clarified my mental model a lotyoutube.comNext.js Conf 2025YouTube video by Vercel 1578
Josh @storyhb.com · 23/10/2025But that requires thought on your part about the tradeoffs and it’s important to decouple “where the data is stored on the server” with the lifetime semantics the static shell and client router are enriched with. You won’t always want to couple these caching considerations 010
Josh @storyhb.com · 23/10/2025Well it’s a matter of performance/cost tradeoff. But that’s not new to Cache Components. Even before this feature you had to decide if you wanted to cache personalized or high cardinality data. And there are a bunch of great services that provide excellent caching capabilities that you can plug in 100
Josh @storyhb.com · 23/10/2025So we are working on an API to opt into runtime prefetching at the segment level that also validates at build time that the prefetch will result in instant UI and figure out if the static prefetch is just as good 110
Josh @storyhb.com · 23/10/2025But we need a way to validate that your runtime prefetch is going to give you something better than what the static prefetch would have otherwise we shouldn’t bother making a runtime prefetch 100
Josh @storyhb.com · 23/10/2025Prefetching static content is cool but if it’s just skeletons that’s only so good. Prefetching real UI is the end goal but since this can be expensive. Runtime prefetching is a way to prefetch UI that has user specific data in it 100
Josh @storyhb.com · 23/10/2025The word “remote” was chosen because an important feature of the default handler is that there is zero network latency to consult the cache and when you introduce a remote cache that isn’t true. Some things would be nice to CPU cache but aren’t worth the network hop 110
Josh @storyhb.com · 23/10/2025But I want to be careful here because with in-process-memory caching it still might make sense to server cache these temporarily since you might have frequent per user reuse when local in time so it isn’t a legal guarantee, just a conceptual one 100
Josh @storyhb.com · 23/10/2025Private is a bit special because it implies “only in the browser” and because of this it allows for cookies and headers on the inside but it also can’t be cached in static prerenders 100