Bump next in upgrade eval fixtures for CVE-2026-94483 (#99838)
## Summary
Bumps `next` in three upgrade eval fixtures that were pinned to versions
affected by CVE-2026-94483 (Image Optimization SSRF via allow-listed
remote patterns; fixed in 16.3.8):
- `future-cache-components-nudge`: 16.3.5 → 16.4.0
- `future-cache-components-same-version`: 16.3.5 → 16.4.0
- `latest-same-major`: 16.2.12 → 16.3.8
A few things needed to be updated to match
- `latest/setup.ts` and `future/setup.ts` mock
`registry.npmjs.org/next/latest` with a hardcoded `target`. That target
is now 16.4.0 (the current `latest`), so the same-version scenarios
still sit on "latest" and the same-major scenario still has a newer
target in the same major.
- `latest-same-major` uses 16.3.8 rather than 16.4.0 because it has to
start below the target in the same major. 16.3.8 is the oldest patched
release; there is no patched 16.2.x.
- The `EVAL.ts` exact-version assertions are updated to match.
The `latest-cross-major`, `latest-nudge` and `future-cache-components`
scenarios now also upgrade to 16.4.0. Their starting versions are
unchanged.
Fixes VULN-16485
Fixes VULN-16486
Fixes VULN-16487
<!-- NEXT_JS_LLM -->