docs/site: bump next 16.2.1 -> 16.3.4 (with eslint-config-next) and vercel
50.37.0 -> 59.11.1, then refresh transitives. The 16.3.x jump is required:
16.2.x hard-pins the vulnerable postcss@8.4.31 and sharp@^0.34.5, while
16.3.x pins postcss@8.5.23 and sharp@^0.35.4.
Five packages are exact-pinned by vercel's own subpackages, so they get
scoped overrides. Scoped rather than blanket because a bare undici override
would drag the 6.x/7.x consumers in the tree down to 5.x.
mobile: bump browserslist 4.28.2 -> 4.28.8.
Two alerts stay open, both in mobile:
- decode-uri-component@0.2.2 (#285). An override to 0.5.0 breaks the tree:
0.5.0 is ESM-only with a default export, but query-string@7.1.3 is CJS and
does `require('decode-uri-component')`, so parse() throws
"decodeComponent is not a function" and takes URL parsing in expo-router
and @react-navigation/core with it. Both pin query-string@^7.1.3; the fix
has to come from upstream moving to query-string 8+.
- image-size@1.2.1 (#179, #180) via metro. No patched version exists on any
release line, so there is nothing to override to.
Verified: docs/site build, tests, lint, tsc and frozen install; mobile
typecheck, 3985 tests and frozen install.