AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Output File Tracing Silently Discards Dependency-Resolution Failures, Causing Standalone Deployments To 500 Or Drop Metadata

When Next.js standalone output is built with Turbopack (or webpack), output file tracing may fail to resolve a dependency but only records the failure in internal warnings that are never surfaced. The resulting .nft.json contains only the package.json of the broken dependency, so runtime require() fails with a deep internal module path. Build exits 0, leading to 500s or silently missing metadata in production.

highConfidence 85%Next.jsAffected V16.2.9Affected V16.3.1-Canary.3

Origin Analysis

Output file tracing (via @vercel/nft for webpack or turbopack-nft for Turbopack) records dependency-resolution failures in warnings/reasons, but the build step only consumes the file list and ignores warnings. For lazy-loaded external packages (e.g., jsdom on serverExternalPackages), the tracing emits a bare package.json without its entry file, so Node's exports map later resolves to a non-existent path at runtime.
1. Create a Next.js app with output: 'standalone' and a route that lazily imports jsdom (or any package on serverExternalPackages with a transitive dependency on lru-cache). 2. Run npm install. 3. Delete the file resolved by lru-cache's exports map under Node conditions, e.g.: rm node_modules/lru-cache/dist/commonjs/node/index.min.js 4. Run npx next build (uses Turbopack). Build exits 0 with no warnings. 5. Deploy the standalone output or run node .next/standalone/server.js. 6. Request the route; observe HTTP 500 or HTTP 200 with missing metadata.

Fixing Code Block

Edge Case Audit

This fix only addresses the webpack tracing path; the Turbopack path (used in the repro) remains silent and would require a separate Rust-side change to route tracing failures through the issues system. Enabling NEXT_STRICT_NFT=1 may break builds that currently have benign optional dependency warnings (e.g., optional peer dependencies), so use it only in CI where such warnings are acceptable to fail. The console.warn logging may be noisy for large projects; consider gating detailed per-warning output behind a debug flag while keeping the summary always visible. Rollback: remove the patch or unset NEXT_STRICT_NFT.

Ecosystem Topology