App Router: `next/script` stylesheets and `nonce` propagation incomplete
#1,517 opened on May 22, 2026
Repository metrics
- Stars
- (8,563 stars)
- PR merge metrics
- (Avg merge 1d 1h) (462 merged PRs in 30d)
Description
This issue was created by an agent analysing CI failures from the Next.js Deploy Suite (vinext
mainvs Next.jsv16.2.6, 2026-05-22).
Problem
The next/script component does not load stylesheets associated with scripts, does not pass through nonce attributes, and does not implement bootstrap-script preinitialization (multiple bootstrap scripts expected; only one rendered).
Stylesheets associated with `next/script` not loaded; nonce missing; preinit bootstrap scripts incomplete
Estimated Impact
~3 test failures across the deploy suite.
Affected Test Suites
test/e2e/app-dir/app/index.test.ts(3 failures)
Recommendation
-
Reproduce first in vinext's own test suite. Add a
<Script>with an associated stylesheet and a CSP nonce, plus a fixture asserting multiple preinit bootstrap scripts. Confirm each fails. -
Load associated stylesheets. When
<Script>has linked stylesheets via the Next.js metadata convention, emit corresponding<link rel="stylesheet">tags. -
Propagate nonce. Add the request nonce to every emitted script/style tag.
-
Implement bootstrap preinit. Match the number of preinit bootstrap scripts Next.js emits for
next/script.
Part of #1328.