convoy: scope bump-next-js (P0 #8 — unblock Vercel deploys) #3

Closed
varutasu wants to merge 3 commits from convoy/bump-next-js into bootstrap/agent-pipeline-v0.5.0
varutasu commented 2026-05-23 00:45:40 -04:00 (Migrated from github.com)

Summary

  • Conductor output: scopes the highest-priority convoy in the launch sequence. Closes P0 ship-blocker #8 (Next.js CVE blocks Vercel deploys) from .convoys/ship-readiness.md.
  • Adds zero production code. The Architect is the next role to run — produces briefs under .convoys/bump-next-js/brief-N-*.md.
  • Until this convoy ships, the entire preview-smoke / visual-diff half of the L3 pipeline is non-functional. That makes this PR a hard prerequisite for every other convoy.

Base branch is bootstrap/agent-pipeline-v0.5.0, not main, because the L2 role files only exist on the bootstrap branch right now. Will rebase onto main after PR #1 lands.

Convoy + Brief

  • Convoy: .convoys/bump-next-js.md (this PR)
  • Brief: N/A (Conductor produces no briefs; Architect does)
  • Classification: feature — with custom skips because the bump has no IA/UX surface
  • Skip: ia, ux, flag
  • Keep: arch, test, review, visual, a11y, design, smoke, qa, docs
  • Next role: role-architect

Acceptance criteria

  • One file added: .convoys/bump-next-js.md
  • Frontmatter follows .cursor/agents/role-conductor.md schema
  • Four required sections present: Why / Scope / Roles invoked / Todos
  • Out-of-scope items explicitly listed and routed to their own convoys
  • Hand-off message ready to paste into a new chat for role-architect
  • Analytics event emitted (.convoys/.metrics.jsonl — gitignored)
  • Target version pre-decided by user input: next@16.2.6 (latest)

Test plan

  • Markdown-only PR. CI lint will pass (no JS/CSS changes); Vercel will still fail (the very thing this convoy fixes — that's expected for the planning PR; the implementation PR is where the unblock actually happens).
  • Sanity-check the convoy file against .cursor/agents/role-conductor.md anti-patterns: one file written, no code, no forbidden skip flags (plan-approval, pr-merge, prod-promote), no automatic role invocation.

Pipeline gates

  • CI: lint
  • Visual diff — N/A on planning PR (will fire on the implementation PR)
  • A11y audit — N/A on planning PR
  • Design-system audit — N/A on planning PR
  • Reviewer report — light; this is documentation
  • Smoke on staging — N/A on planning PR

Notes for reviewer

  • The user explicitly pinned the target version to next@16.2.6 (the major bump) in the success metric. Architect's job becomes "what breaks when we go to 16" rather than "should we go to 15.x or 16.x".
  • next@16 peer-deps allow react@^18.2.0 || ^19.0.0. Current react@18.3.1 is in range — no forced React bump. A React 19 upgrade can be a separate convoy if desired.
  • eslint-config-next is bumped in lockstep to avoid framework / lint-rule version skew.
  • App Router migration is explicitly out of scopetcg-vault is on Pages Router. That migration is a multi-month effort and belongs in its own multi-convoy initiative.
  • Once the implementation PR for this convoy lands, the bootstrap PR's Vercel check should turn green on every subsequent push (because the platform-level CVE block is removed).

Made with Cursor

<!-- pipeline: convoy=bump-next-js, brief=0 skip: ia, ux, flag --> ## Summary - Conductor output: scopes the highest-priority convoy in the launch sequence. Closes P0 ship-blocker **#8** (Next.js CVE blocks Vercel deploys) from `.convoys/ship-readiness.md`. - Adds zero production code. The Architect is the next role to run — produces briefs under `.convoys/bump-next-js/brief-N-*.md`. - **Until this convoy ships, the entire `preview-smoke` / `visual-diff` half of the L3 pipeline is non-functional.** That makes this PR a hard prerequisite for every other convoy. **Base branch is `bootstrap/agent-pipeline-v0.5.0`, not `main`**, because the L2 role files only exist on the bootstrap branch right now. Will rebase onto `main` after PR #1 lands. ## Convoy + Brief - Convoy: `.convoys/bump-next-js.md` (this PR) - Brief: N/A (Conductor produces no briefs; Architect does) - Classification: `feature` — with custom skips because the bump has no IA/UX surface - Skip: `ia, ux, flag` - Keep: `arch, test, review, visual, a11y, design, smoke, qa, docs` - Next role: `role-architect` ## Acceptance criteria - [x] One file added: `.convoys/bump-next-js.md` - [x] Frontmatter follows `.cursor/agents/role-conductor.md` schema - [x] Four required sections present: Why / Scope / Roles invoked / Todos - [x] Out-of-scope items explicitly listed and routed to their own convoys - [x] Hand-off message ready to paste into a new chat for `role-architect` - [x] Analytics event emitted (`.convoys/.metrics.jsonl` — gitignored) - [x] Target version pre-decided by user input: `next@16.2.6` (latest) ## Test plan - Markdown-only PR. CI lint will pass (no JS/CSS changes); Vercel will still fail (the very thing this convoy fixes — that's expected for the planning PR; the implementation PR is where the unblock actually happens). - Sanity-check the convoy file against `.cursor/agents/role-conductor.md` anti-patterns: one file written, no code, no forbidden skip flags (`plan-approval`, `pr-merge`, `prod-promote`), no automatic role invocation. ## Pipeline gates - [ ] CI: lint - [x] Visual diff — N/A on planning PR (will fire on the implementation PR) - [x] A11y audit — N/A on planning PR - [x] Design-system audit — N/A on planning PR - [ ] Reviewer report — light; this is documentation - [x] Smoke on staging — N/A on planning PR ## Notes for reviewer - The user explicitly pinned the target version to `next@16.2.6` (the major bump) in the success metric. Architect's job becomes "what breaks when we go to 16" rather than "should we go to 15.x or 16.x". - `next@16` peer-deps allow `react@^18.2.0 || ^19.0.0`. Current `react@18.3.1` is in range — **no forced React bump.** A React 19 upgrade can be a separate convoy if desired. - `eslint-config-next` is bumped in lockstep to avoid framework / lint-rule version skew. - App Router migration is **explicitly out of scope** — `tcg-vault` is on Pages Router. That migration is a multi-month effort and belongs in its own multi-convoy initiative. - Once the implementation PR for this convoy lands, the bootstrap PR's Vercel check should turn green on every subsequent push (because the platform-level CVE block is removed). Made with [Cursor](https://cursor.com)
vercel[bot] commented 2026-05-23 00:45:45 -04:00 (Migrated from github.com)

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tcg-vault Ready Ready Preview, Comment May 23, 2026 7:04am

Request Review

[vc]: #38tS84o3xtK7g59XcWG+9GjKi1n0B88ACLr/2nOc2gU=:eyJpc01vbm9yZXBvIjp0cnVlLCJ0eXBlIjoiZ2l0aHViIiwicHJvamVjdHMiOlt7Im5hbWUiOiJ0Y2ctdmF1bHQiLCJwcm9qZWN0SWQiOiJwcmpfRjZXOEVvRkd3Y0g3aWVGcnRvRlNlOXdVVkFhNSIsImxpdmVGZWVkYmFjayI6eyJyZXNvbHZlZCI6MCwidW5yZXNvbHZlZCI6MCwidG90YWwiOjAsImxpbmsiOiJ0Y2ctdmF1bHQtZ2l0LWNvbnZveS1idW1wLW5leHQtanMtcmFuZGFsbC1zdGlsbHdlbGxzLXByb2plY3RzLnZlcmNlbC5hcHAifSwiaW5zcGVjdG9yVXJsIjoiaHR0cHM6Ly92ZXJjZWwuY29tL3JhbmRhbGwtc3RpbGx3ZWxscy1wcm9qZWN0cy90Y2ctdmF1bHQvOUNoWlc4NldmSmRqOUg5dEE1UWJuVGJRZjliUyIsInByZXZpZXdVcmwiOiJ0Y2ctdmF1bHQtZ2l0LWNvbnZveS1idW1wLW5leHQtanMtcmFuZGFsbC1zdGlsbHdlbGxzLXByb2plY3RzLnZlcmNlbC5hcHAiLCJuZXh0Q29tbWl0U3RhdHVzIjoiREVQTE9ZRUQiLCJyb290RGlyZWN0b3J5IjpudWxsfV0sInJlcXVlc3RSZXZpZXdVcmwiOiJodHRwczovL3ZlcmNlbC5jb20vdmVyY2VsLWFnZW50L3JlcXVlc3QtcmV2aWV3P293bmVyPXZhcnV0YXN1JnJlcG89dGNnLXZhdWx0JnByPTMifQ== The latest updates on your projects. Learn more about [Vercel for GitHub](https://vercel.link/github-learn-more). | Project | Deployment | Actions | Updated (UTC) | | :--- | :----- | :------ | :------ | | [tcg-vault](https://vercel.com/randall-stillwells-projects/tcg-vault) | ![Ready](https://vercel.com/static/status/ready.svg) [Ready](https://vercel.com/randall-stillwells-projects/tcg-vault/9ChZW86WfJdj9H9tA5QbnTbQf9bS) | [Preview](https://tcg-vault-git-convoy-bump-next-js-randall-stillwells-projects.vercel.app), [Comment](https://vercel.live/open-feedback/tcg-vault-git-convoy-bump-next-js-randall-stillwells-projects.vercel.app?via=pr-comment-feedback-link) | May 23, 2026 7:04am | <a href="https://vercel.com/vercel-agent/request-review?owner=varutasu&repo=tcg-vault&pr=3" rel="noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://agents-vade-review.vercel.sh/request-review-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://agents-vade-review.vercel.sh/request-review-light.svg"><img src="https://agents-vade-review.vercel.sh/request-review-light.svg" alt="Request Review"></picture></a>
varutasu commented 2026-05-23 10:36:48 -04:00 (Migrated from github.com)

Closing as orphan: this PR's work landed on main via PR #4's rebase merge, but under different commit SHAs.

The bump-next-js commits on main (84aa381 convoy: scope bump-next-js, 7540b2c convoy(bump-next-js): plan + brief 1 (Decisions A-D), e57ea17 bump: next 15.4.3 -> 16.2.6, ESLint flat config (v9 fallback), typescript devDep) are patch-equivalent to this PR's chain. GitHub didn't auto-close because the SHAs differ.

No work lost. The bump is fully on main as of e57ea17 and Vercel deploys are unblocked.

For the audit trail: see .convoys/bump-next-js.md § Decisions A–D and .convoys/bump-next-js/brief-1-bump-next-and-migrate-config.md.

Closing as orphan: this PR's work landed on `main` via PR #4's rebase merge, but under different commit SHAs. The bump-next-js commits on `main` (`84aa381 convoy: scope bump-next-js`, `7540b2c convoy(bump-next-js): plan + brief 1 (Decisions A-D)`, `e57ea17 bump: next 15.4.3 -> 16.2.6, ESLint flat config (v9 fallback), typescript devDep`) are patch-equivalent to this PR's chain. GitHub didn't auto-close because the SHAs differ. No work lost. The bump is fully on `main` as of `e57ea17` and Vercel deploys are unblocked. For the audit trail: see `.convoys/bump-next-js.md` § Decisions A–D and `.convoys/bump-next-js/brief-1-bump-next-and-migrate-config.md`.

Pull request closed

Sign in to join this conversation.
No description provided.