Next.js 16.3.0 shipped on August 3 as a minor release, and it changed more defaults than some majors I have lived through. The Turbopack filesystem cache is now on by default for production builds. Cache Components, with cached navigations and app shells, are on by default. The edge runtime is deprecated, the experimental useCache flag is deprecated, and middleware is on notice.
Each of those is a reasonable change and most of them are improvements. The thing I want to point at is the shape of the release. Semantic versioning says a minor adds things without breaking things. A build cache that is suddenly on changes what your continuous integration (CI) pipeline does with disk, with cache keys, and with the question of whether two builds of the same commit are identical. A rendering default that moves to streams changes behavior under load. None of that is a breaking change by the letter. All of it is something I would want to know about before it reached production.
My view is that framework minors now need the same upgrade review gate as majors: a person reads the release notes, lists every changed default, and decides for each one whether it is on or off for this app, before the lockfile moves. Especially where caching changes underneath the pipeline, because a cache that is wrong is the kind of bug that only shows up in the build that mattered.
Does a minor framework upgrade go through review on your team, or straight through the bot?
Photo source: https://photos.robertstowe.com/dolomites

