React gets a full application framework
Next.js turns React into an application framework by deciding how files become routes, where components run, how data reaches a page, and how production output is built. The App Router makes layouts and pages Server Components by default. Interactive code moves behind the use client boundary. Route handlers, metadata, images, fonts, loading states, and streaming all live in the same system. That is useful when a product needs several of those features together.
The trade is a larger model for every developer to learn. Server Components can read from databases and keep secrets away from the browser, while Client Components own state, event handlers, and browser APIs. Marking a file with use client pulls its imported module graph into the client bundle. With React 19 behavior and newer canary features entering through App Router, upgrades deserve staging rather than an automatic version bump.
What happened when we ran it
Our run cloned commit 33b7edf into an unprivileged container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. The checkout contained 30,600 files, about 2,239,314 lines of source, and occupied 148.4 MB. pnpm installed 3,662 packages in 114 seconds, leaving 2,258 MB on disk. The project build succeeded in 96 seconds.
Tests did not finish within our 900-second cap. The final log showed file lists from two fixture applications, including yes-we-can/public/vercel.svg, an app directory, next.config.ts, AGENTS.md, and CLAUDE.md. It did not show a failed assertion, a cause, or a completed test count. We can only call this a timeout while the suite was processing fixtures.
The repository has 38 CI workflow files, a tests directory, and pnpm workspaces, but no root Dockerfile. Those signals match the scale we saw: 3,662 installed packages and more than 2.2 GB on disk before testing. A contributor should target the relevant package or test area first and use the project's contribution instructions. Our run gives no basis for claiming how long a complete suite needs.
A new app starts with Node 20.9 or newer
The official installation guide sets Node 20.9 as the minimum and supports macOS, Windows including WSL, and Linux. create-next-app can generate a working project and install dependencies in one flow. Its recommended defaults include TypeScript, ESLint, Tailwind CSS, App Router, Turbopack, the @/* import alias, and AGENTS.md with a linked CLAUDE.md. Teams can decline those defaults and choose Biome, React Compiler, a src directory, or Pages Router.
That generator removes repetitive setup, but it also hands a new repository several policy choices at once. Review the result instead of treating the scaffold as neutral. Turbopack is the default for development and production builds, while Webpack remains available through a flag. Existing organizations may want their own lint rules, CSS approach, agent instructions, and directory conventions before the first feature branch lands.
Server and client boundaries affect shipped code
The official component guide gives Server Components four concrete jobs: data access near the source, private use of API keys, reducing browser JavaScript, and progressive streaming. Client Components cover state, event handlers, effects, custom hooks, and browser APIs. On first load, Next.js combines prerendered HTML with the React Server Component payload and hydrates client code. Later navigation can use a prefetched payload rather than another complete HTML document.
This boundary is productive once a team treats it as architecture. Put use client high in a tree and more modules enter the browser bundle. Pass values across the boundary and they must be serializable. Fetch request-dependent data and caching behavior changes. Code review should inspect those effects, while tests should cover both first loads and client navigation. A successful next build does not prove that every route has the intended runtime or cache policy.
Deployment choices do not have equal feature support
Next.js documents several targets: a Node server, a Docker container, static export, and platform adapters. Node and Docker keep server features available. Static export removes features that need a server. Adapter quality depends on the target's implementation, so an application that works on one platform still needs acceptance tests before a move. The framework's public API is portable farther than every runtime behavior around caching, images, streaming, and request handling.
The main repository has no Dockerfile despite its 148.4 MB checkout. That is reasonable for framework source, but application teams still own their production image, runtime user, health checks, environment injection, file permissions, and shutdown behavior. Decide the target early. Exercise route handlers, cache invalidation, image optimization, streaming, and any proxy logic against the exact runtime that will serve users.
Active maintenance includes urgent patching
GitHub showed 141,931 stars, 3,727 open issues and pull requests combined, and a last push on August 26, 2026. Those figures describe a very large and active project, not a count of confirmed defects. They also mean advice and examples found outside the official documentation can lag current behavior. Pin releases, read migration notes, and reproduce reported problems against the version you ship.
Release v16.3.3 arrived on August 25, 2026 with fixes for 2 critical security advisories. Both concerned unauthenticated remote code execution, one on Windows-hosted servers and one in the image optimization API when AVIF files are used. That release history makes the operational bargain plain: Next.js has active maintainers, but server deployments must track security notices and patch promptly. A static brochure site that gains little from the server runtime may reasonably choose Astro instead.
Next.js earns its complexity when a React product needs routing, server rendering, server-side data access, and interactive client sections under one release process. The 96-second build in our sandbox shows the snapshot compiled cleanly; the 900-second timeout shows the source repository is expensive to validate wholesale. For application teams prepared to learn its boundaries and keep upgrades controlled, the framework remains an easy shortlist choice.

