FREE1 free audit every month. No card, every finding included.

GUIDESEPISODES

EP 07 · CLAUDEAster × Claude

Claude’s report card, and the one check before you ship

Claude’s knowledge stops in June 2026. Next.js shipped security fixes on September 30, 2026. So we start with the one check to run before you ship. Then the full report card: what Claude is great at, and where it trips you up.

  • 10 min read
  • Beginner
  • Oct 5, 2026
Voxel episode thumbnail tagged EP. 07 on a dark green background with faint code: the headline reads CLAUDE’S JOB INTERVIEW in cream and lime; in a garage office under a lime neon NOW HIRING sign, a skeptical Aster stands behind a wooden desk with a hand on his chin, his laptop at his side and the lime lock on his black shirt; Claude, a small orange block with two tall eye slits, stands on an office chair at the desk; a very long glowing sheet of paper marked CV unrolls off the desk toward the viewer.

COMMENTED CLAUDE? HERE’S THE FIX.

The one check before you ship.

Tick each one off as you do it. Your progress stays on this device.

0 of 3 done

01THE CHECK

Three steps. No code to read.

Why it mattersYour AI set the app up with what it knew at the time. The updates came later.

You don’t have to read a changelog. Ask your AI three things, in this order. It can run the commands for you.

Illustration: in a dark green garage office, voxel Aster sits at a wooden desk with his silver laptop open, one hand on his chin, looking doubtful; Claude, a small orange block with two tall eye slits, side nubs and four short legs, stands on the desk and holds up a glowing lime floating card that lists five rows of package badges with blurred lines, the second row highlighted.
Step one: ask what versions the app runs. Your AI reads the project and hands you the list.
Open the full chapterIncludes steps, code, a table, a note
  1. Ask what you’re running. “What versions of Next.js and my other packages is this app running?” Your AI reads package.json and the lockfile, then tells you. The lockfile is the file that records the exact versions installed.
  2. Tell it to update, then run the app. “Look up the security updates. Move me to the patched versions. Then run the app and tell me what changed.”
  3. Ask again before every launch. A version that is fine today can have a known hole next month.
Illustration: a wooden easel holds a dark board with three big lime steps: the numeral 1 with a magnifying glass, 2 with an up arrow over a progress bar, and 3 with a circular repeat arrow; Claude stands on a small wooden stool pointing at step one, and voxel Aster gives a thumbs-up, his closed silver laptop held at his side away from the lime lock on his black shirt.
The whole check on one board: look, update and run, repeat before every launch.

Want to look yourself?

Open a terminal in your project folder and run these three commands. They only read. They change nothing.

terminal
# What is installed right now?
npm ls next react react-dom

# Which packages have newer versions?
npm outdated

# Which packages have known security problems?
npm audit

npm ls shows what is installed. npm outdated lists newer versions. npm audit lists known security problems in your packages. On pnpm, yarn or bun? Ask your AI for the same three commands.

The Next.js update from September 30

The Next.js team gives the exact commands on its release page. Pick the line that matches your version:

✓ Doterminal
npm install next@15.5.27   # for 15.5
npm install next@16.3.8    # for 16.3

Both commands come from the Next.js September 2026 security release. On another version? The page names updates for 16.3 and 15.5 only. Ask your AI to read it and the Next.js support policy, then tell you where you stand.

Then run the app, every time:

terminal
npm run build   # does it still build?
npm run dev     # open the app and click through it

These are the usual Next.js scripts. If yours differ, ask your AI how to run the app. Click through sign-up, sign-in and checkout before you ship.

What your AI tells youWhat it meansWhat to do
Next.js 16.3.0 to 16.3.7You’re behind the September 30 update for 16.3Move to 16.3.8, then run the app
Next.js 15.5.0 to 15.5.26You’re behind the September 30 update for 15.5Move to 15.5.27, then run the app
Next.js 16.3.8 or 15.5.27You have the September 30 updateGood. Now check your other packages
Another Next.js versionThe release page names updates for 16.3 and 15.5 onlyAsk your AI to check the support policy and plan the upgrade
“You’re on the latest version” (and it looked nothing up)It may be answering from memoryAsk it to read the release page first
npm audit lists problemsSome packages have known holesAsk your AI to update those, then run the app

02WHY IT HAPPENS

Claude knows a lot. Up to June 2026.

Why it mattersAn AI can’t warn you about an update it has never heard of.

Every AI model learns up to a date, then stops. Anthropic’s docs call it the reliable knowledge cutoff. For Claude Fable 5.1, Claude Opus 5.5 and Claude Sonnet 5.5, it is June 2026.

June 2026Claude’s reliable knowledge cutoff (Anthropic docs)
Sept 30, 2026Next.js publishes a security release
v16.3.8and v15.5.27: the versions with the fixes
Illustration: a long wooden workbench in the garage office; on the left Claude holds a small glowing lamp whose warm light ends at a standing paper sign reading JUNE; to the right, in the dark, a bright lime-glowing parcel box carries a paper tag reading SEPT 30, and voxel Aster, laptop closed at his side, points at it.
Claude’s light stops at June. The fix shipped on September 30, out in the dark.
Open the full chapterIncludes a table, a note

On September 30, 2026, the Next.js team published a security release. The fixes are in versions 16.3.8 and 15.5.27, and the page asks people to patch.

Put those two dates side by side. Claude can set up a Next.js version that was fine in June. From memory, it can’t know that an update shipped in September.

WhenWhat happenedWho knows
June 2026Claude’s reliable knowledge stopsClaude
September 30, 2026Next.js ships security fixes in 16.3.8 and 15.5.27The Next.js blog. Claude only if it looks
Your launch dayYour app runs the version it was set up withYou, if you ask

What was in the September 30 release

The release page lists several issues. The most serious one on the list is rated high severity and sits in Image Optimization. The others are rated medium or low.

Not every app is affected by every issue, and the page says who is. One update carries all of the fixes.

Claude says it best in the episode: “I know everything. Up to June.”

03THE REPORT CARD

Claude’s report card, in one table

Why it mattersKnow who you’re hiring before you hand over your app.

Claude is a family of AI models made by Anthropic. Anthropic calls itself an AI safety and research company.

Illustration: a paper report card on a clipboard stands on the wooden desk with five rows of blurred lines: the first two end in big lime ticks and the last three in orange warning triangles, with a small gold star in the corner; Claude stands beside it, proud, and voxel Aster studies it with a raised eyebrow, his laptop closed at his side.
Two strengths, three watch-outs. That’s the whole report card.
Open the full chapterIncludes a table, a note
On the report cardMarkWhere it comes from
Reads about 555,000 words at once+ StrengthAnthropic’s models overview
Writes the code, runs it, fixes what breaks+ StrengthThe Claude Code page
Long answers− Watch outAnthropic’s models overview
Knows nothing after June 2026− Watch outAnthropic’s models overview
Builds what you ask for, not what you forgot to ask− Watch outGitGuardian’s 2026 report and this episode

The family, as Anthropic names it today

The docs list four current models. Not sure which one to pick? The docs say to start with Claude Opus 5.5 for most work.

ModelWhat it’s for (our plain-English summary)Reads at onceReliable knowledge cutoff
Claude Fable 5.1The hardest thinking and very long jobs1M tokensJun 2026
Claude Opus 5.5Long coding jobs and knowledge work1M tokensJun 2026
Claude Sonnet 5.5A mix of speed and smarts1M tokensJun 2026
Claude Haiku 4.5The fastest one200K tokensFeb 2025

And Claude Code?

Claude Code is Anthropic’s coding agent. You hand it a bug to fix, a test to write or an upgrade job that takes days. You steer it from your terminal, your code editor, Slack, the web or your phone.

04GREAT AT

What Claude is great at

Why it mattersIt can hold your whole project in view, and it can do the job itself.

Two strengths matter most when Claude builds your app.

1Mtokens read at once by the three biggest models
555kwords, roughly, in Anthropic’s own count
Illustration: on the wooden desk a gigantic tower of papers and books rises beside Claude; Aster’s single silver laptop stands open showing a lime progress bar and a tick, next to a small voxel house with glowing windows and a wrench leaning on it; voxel Aster looks on, impressed, hands clasped, the lime lock on his shirt fully visible.
It reads the whole pile at once, then writes, runs and fixes the code.
Open the full chapterDetails and sources
  • It reads a huge amount at once. Claude Fable 5.1, Opus 5.5 and Sonnet 5.5 each read 1M tokens in one go. The docs put that at “roughly 555k words”. Claude Haiku 4.5 reads 200K tokens.
  • It does the work, not only the talking. Claude Code works inside your project. It writes the code, runs it and fixes what breaks.

Put together, that feels like having a developer on your team. It is also why the next part matters.

05TRIPS YOU UP

Where it trips people up

Why it mattersThese are habits, not bugs. You can plan for each one.

Three habits catch new builders. None of them is a bug, and each has an easy answer.

Illustration: Claude stands on top of a tall stack of plain white pages pinned with blank speech-bubble notes, and a very long paper scroll of blurred lines unrolls off the desk across the floor; voxel Aster, sceptical, holds up a yellow sticky note showing the number 3 and keeps his closed silver laptop at his side.
Ask for three sentences and you get a scroll. Say the length you want.
Open the full chapterIncludes code, a note

1. Long answers

Claude likes to explain. Anthropic’s own docs say that if you want shorter answers, you should ask for them in your prompt.

add this to your prompt
Answer in three sentences or fewer. No intro, no summary.

Name the length you want: three sentences, five bullet points, one line.

2. It knows nothing after June 2026

New releases, new prices, new security updates: Claude hasn’t heard of them unless it looks them up. So tell it to look.

add this to your prompt
Today is [today's date]. Your knowledge has a cutoff date.
Before you answer, look up the current version and its release notes.
Don't answer from memory.

Swap in the real date. This is the habit behind the check at the top of this page.

3. It builds what you ask for, not what you forgot to ask

Ask for a login page and you get a login page. Nobody asks for “and keep my packages up to date”, so it doesn’t happen by itself. The same goes for keeping secret keys out of your code.

One measured example comes from GitGuardian’s State of Secrets Sprawl 2026 report. It found a 3.2% secret-leak rate in commits made with Claude Code’s help. The baseline across all public GitHub commits was 1.5%.

06THE TAKEAWAY

You interviewed the AI. Now check what it built.

Why it matters“You checked my references. Check what I build.” That’s Claude, in the episode.

In the episode, Aster interviews Claude for a developer job. Near the end he notices something: he interviewed the AI, and nobody interviewed his app.

Illustration: voxel Aster sits behind the wooden interview desk with a clipboard, one hand on his chin, looking across at the empty candidate chair where a small voxel model house with glowing windows sits waiting; Claude stands on the desk beside him and points a side nub at the house.
He interviewed the AI. Nobody interviewed the app.
Open the full chapterDetails and sources

That is the whole lesson. Claude is a strong hire. Its knowledge still stops in June 2026, and security updates keep shipping. So ask what versions you run, update to the patched ones, run the app, and ask again before every launch.

Out-of-date packages are one of the things Aster’s audit looks for. It reads your lockfile, the record of the exact versions installed, and lists package versions with known holes, Next.js included. It also flags secret keys in your code, open Supabase tables and policies, and open Firebase rules.

It doesn’t check webhooks, admin pages, other users’ data or rate limits. Our free guides cover those: verifying Stripe webhooks, admin pages that only hide the button, one user opening another user’s order and protecting a paid AI endpoint.

Two more guides match what the audit looks for: keeping API keys out of the browser and Supabase Row Level Security.

THE QUICK READ

What to take away.
In one minute.

  1. 01

    Claude is a family of AI models made by Anthropic. The current ones are Claude Fable 5.1, Claude Opus 5.5, Claude Sonnet 5.5 and Claude Haiku 4.5.

  2. 02

    Its three biggest models read about 555,000 words at once. And Claude Code writes the code, runs it and fixes what breaks, inside your project.

  3. 03

    Its reliable knowledge stops in June 2026. Anything released later, it has to look up.

  4. 04

    Next.js shipped a security release on September 30, 2026. The fixes are in 16.3.8 and 15.5.27. An app set up from memory can sit on an older version.

  5. 05

    So before every launch: ask what versions you run, update to the patched ones, then run the app.

FOR YOUR CODING AGENT

Let your agent check
your own code.

Paste this into Claude Code, Cursor, Codex, Gemini CLI or Copilot. It only reads and reports; it won’t change your code until you approve.

agent-prompt.md
You are a security reviewer for this codebase. Investigate ONE issue: out-of-date Next.js and other packages that have known security fixes. Your knowledge has a cutoff date, so do not answer from memory.

Where to look:
- `package.json` and the lockfile (`package-lock.json`, `pnpm-lock.yaml`, `yarn.lock` or `bun.lock`): the exact installed versions of `next`, `react`, `react-dom` and every other dependency.
- Run `npm ls next react react-dom` and `npm audit` (or the pnpm, yarn or bun equivalent). Both only read.

How to judge each one:
1. First, tell me your knowledge cutoff date.
2. Look up security releases published after that date. Start with `https://nextjs.org/blog` and each package's security advisories. If you can't go online, say so and ask me to paste the pages.
3. An installed version older than the patched version on its release line is a finding. Use the advisory's own severity.

Report a table: file:line | package and installed version | what's wrong | severity (critical, high, medium, low) | the minimal fix (the exact install command and the patched version).

Rules: read and report first. Don't modify any file until I approve. Never print secrets or tokens: mask them. After I approve, update only to the patched versions, run the build and the app, and report what changed and anything that broke.

Then ask me which fixes to apply.

QUESTIONS PEOPLE ASK

Good questions.
Short answers.

Who makes Claude, and which models are current?

Anthropic makes Claude. It calls itself an AI safety and research company. Its docs list four current models: Claude Fable 5.1, Claude Opus 5.5, Claude Sonnet 5.5 and Claude Haiku 4.5.

What is Claude’s knowledge cutoff?

For Claude Fable 5.1, Opus 5.5 and Sonnet 5.5, Anthropic’s docs list a reliable knowledge cutoff of June 2026. For Claude Haiku 4.5 it is February 2025. Anything newer, Claude has to look up.

Why would Claude set up an old version of Next.js?

It works from what it knew when it stopped learning. A version that was current in June 2026 can be behind a security release today. Next.js published one on September 30, 2026.

How do I see which Next.js version my app runs?

Ask your AI: “What version of Next.js is this app running?” Or run npm ls next in your project folder. The number is also in package.json.

How do I update Next.js?

The Next.js release page gives the commands. Run npm install next@16.3.8 if you are on 16.3, or npm install next@15.5.27 if you are on 15.5. Then run the app and click through it before you ship.

Will updating break my app?

These two updates stay on the same version line, so they are meant to be small. Still, run the build, open the app and test sign-in and payments before you ship. If something breaks, your AI can read the error and help you repair it.

How do I get shorter answers from Claude?

Ask for them. Anthropic’s docs say to adjust your prompt if you want more concise replies. Try: “Answer in three sentences or fewer.”

Does Aster check for out-of-date packages?

Yes. Aster’s audit lists package versions with known holes, Next.js included. It also flags secret keys in code, open Supabase tables and policies, and open Firebase rules. It doesn’t check webhooks, admin pages or rate limits. A clean report means none of Aster’s checks matched, not that your app is secure.

Claude is a strong hire. It reads a huge amount at once, and Claude Code writes, runs and repairs code inside your project. Its knowledge also stops in June 2026, and security updates keep shipping. So before every launch, ask what versions you run, update to the patched ones and run the app. A free Aster audit can check your packages and take a second look at the rest of your repo.
Source notebook9 links
  1. Next.js Blog: September 2026 Security Release (September 30, 2026)
  2. Next.js: Support Policy (Active LTS and Maintenance LTS)
  3. npm Docs: npm ls (what is installed)
  4. npm Docs: npm outdated (newer versions)
  5. npm Docs: npm audit (known security problems)
  6. Anthropic Docs: Models overview (current models, context window, reliable knowledge cutoff)
  7. Anthropic: Company
  8. Claude Code by Anthropic (product page)
  9. GitGuardian: The State of Secrets Sprawl 2026

Done with the guide?
Let Aster check the rest.

1 free audit every month. Aster reads your code, env files, database rules and packages. You get each finding in plain English, with the file and line.

Aster

CHECKING

YOUR GUIDE TO ASTER

Hi, I’m Aster.
Ask me what Aster checks.

I can’t see your code from here. Please don’t paste secrets or private code.

Prepared answers are always available.