GUIDESEPISODES
Claude’s report card, and the one check before you ship
Claude’s knowledge stops in June 2026. Next.js shipped security fixes on September 30, 2026. So we start with the one check to run before you ship. Then the full report card: what Claude is great at, and where it trips you up.

COMMENTED CLAUDE? HERE’S THE FIX.
The one check before you ship.
Tick each one off as you do it. Your progress stays on this device.
0 of 3 done
A free audit can take a second look at the rest of your code.
01THE CHECK
Three steps. No code to read.
Why it mattersYour AI set the app up with what it knew at the time. The updates came later.
You don’t have to read a changelog. Ask your AI three things, in this order. It can run the commands for you.

Open the full chapterIncludes steps, code, a table, a note
- Ask what you’re running. “What versions of Next.js and my other packages is this app running?” Your AI reads
package.jsonand the lockfile, then tells you. The lockfile is the file that records the exact versions installed. - Tell it to update, then run the app. “Look up the security updates. Move me to the patched versions. Then run the app and tell me what changed.”
- Ask again before every launch. A version that is fine today can have a known hole next month.

Want to look yourself?
Open a terminal in your project folder and run these three commands. They only read. They change nothing.
# What is installed right now?
npm ls next react react-dom
# Which packages have newer versions?
npm outdated
# Which packages have known security problems?
npm auditnpm ls shows what is installed. npm outdated lists newer versions. npm audit lists known security problems in your packages. On pnpm, yarn or bun? Ask your AI for the same three commands.
The Next.js update from September 30
The Next.js team gives the exact commands on its release page. Pick the line that matches your version:
npm install next@15.5.27 # for 15.5
npm install next@16.3.8 # for 16.3Both commands come from the Next.js September 2026 security release. On another version? The page names updates for 16.3 and 15.5 only. Ask your AI to read it and the Next.js support policy, then tell you where you stand.
Then run the app, every time:
npm run build # does it still build?
npm run dev # open the app and click through itThese are the usual Next.js scripts. If yours differ, ask your AI how to run the app. Click through sign-up, sign-in and checkout before you ship.
| What your AI tells you | What it means | What to do |
|---|---|---|
| Next.js 16.3.0 to 16.3.7 | You’re behind the September 30 update for 16.3 | Move to 16.3.8, then run the app |
| Next.js 15.5.0 to 15.5.26 | You’re behind the September 30 update for 15.5 | Move to 15.5.27, then run the app |
| Next.js 16.3.8 or 15.5.27 | You have the September 30 update | Good. Now check your other packages |
| Another Next.js version | The release page names updates for 16.3 and 15.5 only | Ask your AI to check the support policy and plan the upgrade |
| “You’re on the latest version” (and it looked nothing up) | It may be answering from memory | Ask it to read the release page first |
npm audit lists problems | Some packages have known holes | Ask your AI to update those, then run the app |
02WHY IT HAPPENS
Claude knows a lot. Up to June 2026.
Why it mattersAn AI can’t warn you about an update it has never heard of.
Every AI model learns up to a date, then stops. Anthropic’s docs call it the reliable knowledge cutoff. For Claude Fable 5.1, Claude Opus 5.5 and Claude Sonnet 5.5, it is June 2026.

Open the full chapterIncludes a table, a note
On September 30, 2026, the Next.js team published a security release. The fixes are in versions 16.3.8 and 15.5.27, and the page asks people to patch.
Put those two dates side by side. Claude can set up a Next.js version that was fine in June. From memory, it can’t know that an update shipped in September.
| When | What happened | Who knows |
|---|---|---|
| June 2026 | Claude’s reliable knowledge stops | Claude |
| September 30, 2026 | Next.js ships security fixes in 16.3.8 and 15.5.27 | The Next.js blog. Claude only if it looks |
| Your launch day | Your app runs the version it was set up with | You, if you ask |
What was in the September 30 release
The release page lists several issues. The most serious one on the list is rated high severity and sits in Image Optimization. The others are rated medium or low.
Not every app is affected by every issue, and the page says who is. One update carries all of the fixes.
Claude says it best in the episode: “I know everything. Up to June.”
03THE REPORT CARD
Claude’s report card, in one table
Why it mattersKnow who you’re hiring before you hand over your app.
Claude is a family of AI models made by Anthropic. Anthropic calls itself an AI safety and research company.

Open the full chapterIncludes a table, a note
| On the report card | Mark | Where it comes from |
|---|---|---|
| Reads about 555,000 words at once | + Strength | Anthropic’s models overview |
| Writes the code, runs it, fixes what breaks | + Strength | The Claude Code page |
| Long answers | − Watch out | Anthropic’s models overview |
| Knows nothing after June 2026 | − Watch out | Anthropic’s models overview |
| Builds what you ask for, not what you forgot to ask | − Watch out | GitGuardian’s 2026 report and this episode |
The family, as Anthropic names it today
The docs list four current models. Not sure which one to pick? The docs say to start with Claude Opus 5.5 for most work.
| Model | What it’s for (our plain-English summary) | Reads at once | Reliable knowledge cutoff |
|---|---|---|---|
| Claude Fable 5.1 | The hardest thinking and very long jobs | 1M tokens | Jun 2026 |
| Claude Opus 5.5 | Long coding jobs and knowledge work | 1M tokens | Jun 2026 |
| Claude Sonnet 5.5 | A mix of speed and smarts | 1M tokens | Jun 2026 |
| Claude Haiku 4.5 | The fastest one | 200K tokens | Feb 2025 |
And Claude Code?
Claude Code is Anthropic’s coding agent. You hand it a bug to fix, a test to write or an upgrade job that takes days. You steer it from your terminal, your code editor, Slack, the web or your phone.
04GREAT AT
What Claude is great at
Why it mattersIt can hold your whole project in view, and it can do the job itself.
Two strengths matter most when Claude builds your app.

Open the full chapterDetails and sources
- It reads a huge amount at once. Claude Fable 5.1, Opus 5.5 and Sonnet 5.5 each read 1M tokens in one go. The docs put that at “roughly 555k words”. Claude Haiku 4.5 reads 200K tokens.
- It does the work, not only the talking. Claude Code works inside your project. It writes the code, runs it and fixes what breaks.
Put together, that feels like having a developer on your team. It is also why the next part matters.
05TRIPS YOU UP
Where it trips people up
Why it mattersThese are habits, not bugs. You can plan for each one.
Three habits catch new builders. None of them is a bug, and each has an easy answer.

Open the full chapterIncludes code, a note
1. Long answers
Claude likes to explain. Anthropic’s own docs say that if you want shorter answers, you should ask for them in your prompt.
Answer in three sentences or fewer. No intro, no summary.Name the length you want: three sentences, five bullet points, one line.
2. It knows nothing after June 2026
New releases, new prices, new security updates: Claude hasn’t heard of them unless it looks them up. So tell it to look.
Today is [today's date]. Your knowledge has a cutoff date.
Before you answer, look up the current version and its release notes.
Don't answer from memory.Swap in the real date. This is the habit behind the check at the top of this page.
3. It builds what you ask for, not what you forgot to ask
Ask for a login page and you get a login page. Nobody asks for “and keep my packages up to date”, so it doesn’t happen by itself. The same goes for keeping secret keys out of your code.
One measured example comes from GitGuardian’s State of Secrets Sprawl 2026 report. It found a 3.2% secret-leak rate in commits made with Claude Code’s help. The baseline across all public GitHub commits was 1.5%.
06THE TAKEAWAY
You interviewed the AI. Now check what it built.
Why it matters“You checked my references. Check what I build.” That’s Claude, in the episode.
In the episode, Aster interviews Claude for a developer job. Near the end he notices something: he interviewed the AI, and nobody interviewed his app.

Open the full chapterDetails and sources
That is the whole lesson. Claude is a strong hire. Its knowledge still stops in June 2026, and security updates keep shipping. So ask what versions you run, update to the patched ones, run the app, and ask again before every launch.
Out-of-date packages are one of the things Aster’s audit looks for. It reads your lockfile, the record of the exact versions installed, and lists package versions with known holes, Next.js included. It also flags secret keys in your code, open Supabase tables and policies, and open Firebase rules.
It doesn’t check webhooks, admin pages, other users’ data or rate limits. Our free guides cover those: verifying Stripe webhooks, admin pages that only hide the button, one user opening another user’s order and protecting a paid AI endpoint.
Two more guides match what the audit looks for: keeping API keys out of the browser and Supabase Row Level Security.
THE QUICK READ
What to take away.
In one minute.
- 01
Claude is a family of AI models made by Anthropic. The current ones are Claude Fable 5.1, Claude Opus 5.5, Claude Sonnet 5.5 and Claude Haiku 4.5.
- 02
Its three biggest models read about 555,000 words at once. And Claude Code writes the code, runs it and fixes what breaks, inside your project.
- 03
Its reliable knowledge stops in June 2026. Anything released later, it has to look up.
- 04
Next.js shipped a security release on September 30, 2026. The fixes are in 16.3.8 and 15.5.27. An app set up from memory can sit on an older version.
- 05
So before every launch: ask what versions you run, update to the patched ones, then run the app.
FOR YOUR CODING AGENT
Let your agent check
your own code.
Paste this into Claude Code, Cursor, Codex, Gemini CLI or Copilot. It only reads and reports; it won’t change your code until you approve.
You are a security reviewer for this codebase. Investigate ONE issue: out-of-date Next.js and other packages that have known security fixes. Your knowledge has a cutoff date, so do not answer from memory. Where to look: - `package.json` and the lockfile (`package-lock.json`, `pnpm-lock.yaml`, `yarn.lock` or `bun.lock`): the exact installed versions of `next`, `react`, `react-dom` and every other dependency. - Run `npm ls next react react-dom` and `npm audit` (or the pnpm, yarn or bun equivalent). Both only read. How to judge each one: 1. First, tell me your knowledge cutoff date. 2. Look up security releases published after that date. Start with `https://nextjs.org/blog` and each package's security advisories. If you can't go online, say so and ask me to paste the pages. 3. An installed version older than the patched version on its release line is a finding. Use the advisory's own severity. Report a table: file:line | package and installed version | what's wrong | severity (critical, high, medium, low) | the minimal fix (the exact install command and the patched version). Rules: read and report first. Don't modify any file until I approve. Never print secrets or tokens: mask them. After I approve, update only to the patched versions, run the build and the app, and report what changed and anything that broke. Then ask me which fixes to apply.
QUESTIONS PEOPLE ASK
Good questions.
Short answers.
Who makes Claude, and which models are current?
Anthropic makes Claude. It calls itself an AI safety and research company. Its docs list four current models: Claude Fable 5.1, Claude Opus 5.5, Claude Sonnet 5.5 and Claude Haiku 4.5.
What is Claude’s knowledge cutoff?
For Claude Fable 5.1, Opus 5.5 and Sonnet 5.5, Anthropic’s docs list a reliable knowledge cutoff of June 2026. For Claude Haiku 4.5 it is February 2025. Anything newer, Claude has to look up.
Why would Claude set up an old version of Next.js?
It works from what it knew when it stopped learning. A version that was current in June 2026 can be behind a security release today. Next.js published one on September 30, 2026.
How do I see which Next.js version my app runs?
Ask your AI: “What version of Next.js is this app running?” Or run npm ls next in your project folder. The number is also in package.json.
How do I update Next.js?
The Next.js release page gives the commands. Run npm install next@16.3.8 if you are on 16.3, or npm install next@15.5.27 if you are on 15.5. Then run the app and click through it before you ship.
Will updating break my app?
These two updates stay on the same version line, so they are meant to be small. Still, run the build, open the app and test sign-in and payments before you ship. If something breaks, your AI can read the error and help you repair it.
How do I get shorter answers from Claude?
Ask for them. Anthropic’s docs say to adjust your prompt if you want more concise replies. Try: “Answer in three sentences or fewer.”
Does Aster check for out-of-date packages?
Yes. Aster’s audit lists package versions with known holes, Next.js included. It also flags secret keys in code, open Supabase tables and policies, and open Firebase rules. It doesn’t check webhooks, admin pages or rate limits. A clean report means none of Aster’s checks matched, not that your app is secure.
Claude is a strong hire. It reads a huge amount at once, and Claude Code writes, runs and repairs code inside your project. Its knowledge also stops in June 2026, and security updates keep shipping. So before every launch, ask what versions you run, update to the patched ones and run the app. A free Aster audit can check your packages and take a second look at the rest of your repo.
Source notebook9 links
- Next.js Blog: September 2026 Security Release (September 30, 2026)
- Next.js: Support Policy (Active LTS and Maintenance LTS)
- npm Docs: npm ls (what is installed)
- npm Docs: npm outdated (newer versions)
- npm Docs: npm audit (known security problems)
- Anthropic Docs: Models overview (current models, context window, reliable knowledge cutoff)
- Anthropic: Company
- Claude Code by Anthropic (product page)
- GitGuardian: The State of Secrets Sprawl 2026
