Repository navigation
fix(deps): update all non-major dependencies - #8
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
18 times, most recently
from
September 27, 2026 10:20
e17fa42 to
d4f6c2f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
October 1, 2026 18:07
38ce7dc to
953fd7e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 1, 2026 21:50
953fd7e to
4d420de
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
13 times, most recently
from
October 6, 2026 01:29
590122d to
7a110b9
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 6, 2026 15:25
7a110b9 to
347f607
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.0.65→2.0.673.0.62→3.0.634.0.126→4.0.1285.39.2→5.39.35.39.2→5.39.35.24.2→5.24.35.39.2→5.39.31.2.138→1.2.1404.5.2→4.6.00.22.0→0.23.09.2.4→9.2.69.2.4→9.2.69.2.4→9.2.69.2.4→9.2.626.6.3→26.6.41.44.0→1.45.01.44.0→1.45.01.44.0→1.45.01.44.0→1.45.01.44.0→1.45.00.24.0→0.26.07.0.126→7.0.1284.5.2→4.6.00.7.0→0.7.16.10.1→6.10.310.34.5+sha512.a4ee05f2f73658255bd6a89859c065a45c28a57daefae2c893a168ee2b73168c37b91e83e57ea67654ad03f03031746430e8bce38e362e042605fb8abc80192e→10.34.65.5.5→5.6.05.57.1→5.57.23.3.11→3.3.12Release Notes
vercel/ai (@ai-sdk/mcp)
v2.0.67Compare Source
Patch Changes
bba3927: feat(mcp): export MCPClientError for typed MCP failure handling9384b92: fix(mcp): reject SSE startup when the connection closes before an endpoint is received575383e: fix(mcp): preserve OAuth credentials when callback codes are rejected2959d35]59116e6]v2.0.66Compare Source
Patch Changes
3ff0f54: feat(mcp): add AuthorizationServerMismatchError for OAuth authorization server pin mismatchesvercel/ai (@ai-sdk/openai-compatible)
v3.0.63Compare Source
Patch Changes
2959d35]59116e6]vercel/ai (@ai-sdk/vue)
v4.0.128Compare Source
Patch Changes
0fe8c67]2959d35]0ca1ab9]d6b42fd]ed6e72d]59116e6]2136151]v4.0.127Compare Source
Patch Changes
158a718]bb8d33e]284dc11]ba8afe9]chakra-ui/ark (@ark-ui/react)
v5.39.3Compare Source
Fixed
Toggle.Indicator,AngleSlider.Marker,AngleSlider.ValueTextandListbox.ItemTextrenderspan,Popover.Titlerendersh2, and Svelte'sNumberInput.Scrubberrendersdiv.SelectIntlTranslations,SelectPositioningOptions,SelectScrollToIndexDetailsandSelectSelectionDetails.ClipboardValueChangeDetails.DateInputPlaceholderChangeDetails.ImageCropperRect.QrCodeValueChangeDetails.StepInvalidDetails. In Vue, this fixes TS2883 ("cannot be named without a reference to …") whenemitting declarations for a component that wraps one of these roots, for example a generic
Select.Rootwrapperbuilt with pnpm.
Field.ErrorTextnot being announced by VoiceOver and Narrator. It is now linked viaaria-describedbyinstead ofaria-errormessage, since screen reader support foraria-errormessageis stillincomplete.
Toasterdropping the group props it accepts.dirandgetRootNodewere typed on the component but neverreached the group machine — the locale and environment contexts always won, and both props were spread onto the region
element instead. The toast region's
aria-labelis now settable through alabelprop, which is forwarded togetGroupProps.Tour.Spotlightdisappearing immediately when the tour closes, so its exit animation can run.TourStepsChangeDetailsforonStepsChange, and add flatTour*aliasesfor the step, action, and callback detail types.
initialFocusElcan now returnfalseto open without moving focus. Returningnullstill usesthe default.
api.setCrop(rect)to place the crop area programmatically, in viewport coordinates. Therect is constrained like
initialCrop, and unlikeapi.reset()it keeps the current zoom, rotation, flip, and pan.api.typeandapi.getPageUrl(page), so custom parts can tell whether the controls are buttonsor links and build a page's URL.
allowMouseDragadvancing a full page per pointer move in Vue.strategy="absolute"placing the panel outside its boundary.Alt+Arrowresizing ignoringaspectRatioandcropShape="circle".highlightOnHovernow selects the full range, and Shift+arrow can reverse direction.autoFocus={false}being ignored for modal popovers.z-indexon the positioner being ignoredwhen the content has no stacking level.
intercepting clicks.
formatOptionschanges to a subset of the previous options.onActiveChangereporting the previousactiveIdsandactiveItems, which kept a controlled TOCstuck on the old section.
replaced, and the backdrop leaving part of the page undimmed on resize.
derived_inertwarnings when a component's cleanup runs after it unmounts.and data URLs.
Illegal invocationthrown on setup when a tool like Storybook has replacedHTMLElement.prototype.focus.chakra-ui/ark (@ark-ui/solid)
v5.39.3Compare Source
Fixed
Toggle.Indicator,AngleSlider.Marker,AngleSlider.ValueTextandListbox.ItemTextrenderspan,Popover.Titlerendersh2, and Svelte'sNumberInput.Scrubberrendersdiv.SelectIntlTranslations,SelectPositioningOptions,SelectScrollToIndexDetailsandSelectSelectionDetails.ClipboardValueChangeDetails.DateInputPlaceholderChangeDetails.ImageCropperRect.QrCodeValueChangeDetails.StepInvalidDetails. In Vue, this fixes TS2883 ("cannot be named without a reference to …") whenemitting declarations for a component that wraps one of these roots, for example a generic
Select.Rootwrapperbuilt with pnpm.
Field.ErrorTextnot being announced by VoiceOver and Narrator. It is now linked viaaria-describedbyinstead ofaria-errormessage, since screen reader support foraria-errormessageis stillincomplete.
Tour.Contentunmounting before its exit animation finishes when usinglazyMountandunmountOnExit.TreeView.NodeCheckboxIndicatornot updating when a node is checked or becomes indeterminate.useTreeViewlosing the node type, soselectedNodes,expandedNodesandfocusedNodearetyped as
Tinstead ofTreeNode.NumberInput.ValueTextrendering empty when used without children. It now displays the currentvalue.
Select.ValueTextignoring custom children.Toasterdropping the group props it accepts.dirandgetRootNodewere typed on the component but neverreached the group machine — the locale and environment contexts always won, and both props were spread onto the region
element instead. The toast region's
aria-labelis now settable through alabelprop, which is forwarded togetGroupProps.Tour.Spotlightdisappearing immediately when the tour closes, so its exit animation can run.TourStepsChangeDetailsforonStepsChange, and add flatTour*aliasesfor the step, action, and callback detail types.
initialFocusElcan now returnfalseto open without moving focus. Returningnullstill usesthe default.
api.setCrop(rect)to place the crop area programmatically, in viewport coordinates. Therect is constrained like
initialCrop, and unlikeapi.reset()it keeps the current zoom, rotation, flip, and pan.api.typeandapi.getPageUrl(page), so custom parts can tell whether the controls are buttonsor links and build a page's URL.
allowMouseDragadvancing a full page per pointer move in Vue.strategy="absolute"placing the panel outside its boundary.Alt+Arrowresizing ignoringaspectRatioandcropShape="circle".highlightOnHovernow selects the full range, and Shift+arrow can reverse direction.autoFocus={false}being ignored for modal popovers.z-indexon the positioner being ignoredwhen the content has no stacking level.
intercepting clicks.
formatOptionschanges to a subset of the previous options.onActiveChangereporting the previousactiveIdsandactiveItems, which kept a controlled TOCstuck on the old section.
replaced, and the backdrop leaving part of the page undimmed on resize.
derived_inertwarnings when a component's cleanup runs after it unmounts.and data URLs.
Illegal invocationthrown on setup when a tool like Storybook has replacedHTMLElement.prototype.focus.chakra-ui/ark (@ark-ui/svelte)
v5.24.3Compare Source
Fixed
Toggle.Indicator,AngleSlider.Marker,AngleSlider.ValueTextandListbox.ItemTextrenderspan,Popover.Titlerendersh2, and Svelte'sNumberInput.Scrubberrendersdiv.SelectIntlTranslations,SelectPositioningOptions,SelectScrollToIndexDetailsandSelectSelectionDetails.ClipboardValueChangeDetails.DateInputPlaceholderChangeDetails.ImageCropperRect.QrCodeValueChangeDetails.StepInvalidDetails. In Vue, this fixes TS2883 ("cannot be named without a reference to …") whenemitting declarations for a component that wraps one of these roots, for example a generic
Select.Rootwrapperbuilt with pnpm.
Field.ErrorTextnot being announced by VoiceOver and Narrator. It is now linked viaaria-describedbyinstead ofaria-errormessage, since screen reader support foraria-errormessageis stillincomplete.
AngleSlider.ValueTextrendering empty when used without children. It now displays the currentvalue in degrees.
rendersnippet on everyContextcomponent. 55 of the 63 takerender;Avatar,Progress,QrCodeandTimertookapi, andDialog,Drawer,MarqueeandRadioGrouptookchildren. Those eight now takerendertoo, and keep
api/childrenas deprecated aliases, so existing code keeps working.Dialog.DescriptionandPopover.Descriptionrendering apelement. React, Solid and Vue render adiv, so astylesheet or a nested block element written against one stack broke on the other.
FileUpload.ItemGroupasul,Menu.Separatorashr,Slider.ValueTextasspan, andDatePicker.TableCellTrigger,Steps.List,TreeView.BranchTriggerandTreeView.Itemasdiv, matching the otherframeworks.
bind:refstayingnullwhen a component renders throughasChild. The factory boundrefonly on the elementit renders itself, so in
asChildmode the caller's element was never assigned. The props function now carries anattachment that sets
refto the child element, matching React, where the ref reaches theasChildchild.Fieldsetnamespace's prop types under their namespaced names. Every other Svelte namespace aliases them —Field.RootProps,Dialog.RootProps,Accordion.ItemPropsand so on — butfieldset.tsre-exported the flatFieldsetRootProps/FieldsetLegendPropsnames, soFieldset.RootPropsand its siblings did not resolve and theBasePropsvariants were not exported at all. This matches the React package, whoseFieldsetnamespace alreadyaliases both.
bind:expandedValue,bind:selectedValue,bind:checkedValueandbind:focusedValuenotsyncing, and the tree not re-rendering when
datachanges.useJsonTreeViewnow also reacts todatachanges.asChildprops function rejecting an SVG child. It returnedHTMLAttributes<HTMLElement>, whose eventhandlers don't accept an
SVGElement, so<svg {...props()}>failed to typecheck without a cast. It now returnsattributes any element accepts, which keeps spreading a part's props onto a different element (a trigger rendered as
<a>) working.HTMLProps,HTMLTag,PolymorphicProps,PropsFnandRefAttribute, so wrappers can type their ownpolymorphic props the way
@ark-ui/reactexportsHTMLArkPropsandPolymorphicProps.Portalleaving its content in the DOM when unmounted immediately after mounting.Portalnot moving its content when thecontainerprop changes.Select.ValueTextrendering itsplaceholderas a DOM attribute. The component spread every prop onto theunderlying
span, so the fallback text showed up asplaceholder="…"in the markup.Listbox.ValueTextandDatePicker.ValueTextalready split it out.Tabs.Contentomitting the presence props. The content merged only the machine props, so it never carrieddata-state="open" | "closed"(the React, Solid and Vue implementations do) and it was hidden the moment the tabchanged, cutting exit animations short.
Tooltip.Rootignoring a controlledopenprop. The root destructuredopenout of its props and never passedit to the machine, so
<Tooltip.Root open={true}>(or abind:openthe parent drives) rendered a closed tooltip. Theother popper roots (
Dialog,Popover,HoverCard) already forward it.Toasterdropping the group props it accepts.dirandgetRootNodewere typed on the component but neverreached the group machine — the locale and environment contexts always won, and both props were spread onto the region
element instead. The toast region's
aria-labelis now settable through alabelprop, which is forwarded togetGroupProps.Tour.Spotlightdisappearing immediately when the tour closes, so its exit animation can run.TourStepsChangeDetailsforonStepsChange, and add flatTour*aliasesfor the step, action, and callback detail types.
initialFocusElcan now returnfalseto open without moving focus. Returningnullstill usesthe default.
api.setCrop(rect)to place the crop area programmatically, in viewport coordinates. Therect is constrained like
initialCrop, and unlikeapi.reset()it keeps the current zoom, rotation, flip, and pan.api.typeandapi.getPageUrl(page), so custom parts can tell whether the controls are buttonsor links and build a page's URL.
allowMouseDragadvancing a full page per pointer move in Vue.strategy="absolute"placing the panel outside its boundary.Alt+Arrowresizing ignoringaspectRatioandcropShape="circle".highlightOnHovernow selects the full range, and Shift+arrow can reverse direction.autoFocus={false}being ignored for modal popovers.z-indexon the positioner being ignoredwhen the content has no stacking level.
intercepting clicks.
formatOptionschanges to a subset of the previous options.onActiveChangereporting the previousactiveIdsandactiveItems, which kept a controlled TOCstuck on the old section.
replaced, and the backdrop leaving part of the page undimmed on resize.
derived_inertwarnings when a component's cleanup runs after it unmounts.and data URLs.
Illegal invocationthrown on setup when a tool like Storybook has replacedHTMLElement.prototype.focus.chakra-ui/ark (@ark-ui/vue)
v5.39.3Compare Source
Fixed
Toggle.Indicator,AngleSlider.Marker,AngleSlider.ValueTextandListbox.ItemTextrenderspan,Popover.Titlerendersh2, and Svelte'sNumberInput.Scrubberrendersdiv.SelectIntlTranslations,SelectPositioningOptions,SelectScrollToIndexDetailsandSelectSelectionDetails.ClipboardValueChangeDetails.DateInputPlaceholderChangeDetails.ImageCropperRect.QrCodeValueChangeDetails.StepInvalidDetails. In Vue, this fixes TS2883 ("cannot be named without a reference to …") whenemitting declarations for a component that wraps one of these roots, for example a generic
Select.Rootwrapperbuilt with pnpm.
Field.ErrorTextnot being announced by VoiceOver and Narrator. It is now linked viaaria-describedbyinstead ofaria-errormessage, since screen reader support foraria-errormessageis stillincomplete.
Rootnot emittingvalueChangeandupdate:modelValue, sov-modelstayed stale aftersetValue()from context.QrCode.Contextbeing undefined because it was exported under the wrong name.Toasterdropping the group props it accepts.dirandgetRootNodewere typed on the component but neverreached the group machine — the locale and environment contexts always won, and both props were spread onto the region
element instead. The toast region's
aria-labelis now settable through alabelprop, which is forwarded togetGroupProps.Tour.Spotlightdisappearing immediately when the tour closes, so its exit animation can run. It also now setsdata-state.TourStepsChangeDetailsforonStepsChange, and add flatTour*aliasesfor the step, action, and callback detail types.
aria-labelandaria-labelledbybeing ignored onAngleSlider.Root,Slider.Root,Dialog.Root,Menu.Root,and
Tooltip.Root. For example,<AngleSlider.Root aria-label="Rotation">now names the thumb.Avatar.Image,ImageCropper.Image,Menu.Separator, andPasswordInput.Inputrendering nothing when usingasChild.ImageCropper.Rootignoring all of its props, such asfixedCropArea,aspectRatio, andinitialCrop.Accordion.Itemnot inheritingdisabledfromAccordion.Root.ColorPicker.SwatchandColorPicker.ValueSwatchdropping the alpha channel by default.DatePicker.Inputnot committing the typed date on blur by default.NavigationMenu.Linknot closing the menu when clicked.Toc.Rootnot auto-scrolling to the active item by default.Contextslot items typed asunknowninside generic wrapper components.Cannot find name '__VLS_Slots'type errors whenskipLibCheckis disabled.class,styleand other attributes not being forwarded to the rendered<mark>elements.v-model:expanded-value,v-model:selected-value,v-model:checked-valueandv-model:focused-valuenot updating, and the tree not re-rendering whendatachanges.useJsonTreeViewnow alsoreacts to
datachanges.selectevent not being emitted when an item is selected.requestDismissevent not being emitted when a parent layer closes.NumberInput.ValueTextrendering empty when used without a default slot. It now displays thecurrent value.
Tour.RootEmitsdeclaringstatusChange,stepChangeand other machine events thatTour.Rootnever emits. It now only declares
enterCompleteandexitComplete. PassonStatusChange,onStepChangeand theother callbacks to
useTourinstead.enterCompleteandexitCompleteevent descriptions being swapped.TreeView.RootEmits<T>anduseTreeViewlosing the node type, soselectedNodes,expandedNodesandfocusedNodeare typed asTinstead ofTreeNode.fallbackandindeterminateprops fromTreeView.NodeCheckboxIndicator. They were neverrendered; use the
#fallbackand#indeterminateslots instead.initialFocusElcan now returnfalseto open without moving focus. Returningnullstill usesthe default.
api.setCrop(rect)to place the crop area programmatically, in viewport coordinates. Therect is constrained like
initialCrop, and unlikeapi.reset()it keeps the current zoom, rotation, flip, and pan.api.typeandapi.getPageUrl(page), so custom parts can tell whether the controls are buttonsor links and build a page's URL.
allowMouseDragadvancing a full page per pointer move in Vue.strategy="absolute"placing the panel outside its boundary.Alt+Arrowresizing ignoringaspectRatioandcropShape="circle".highlightOnHovernow selects the full range, and Shift+arrow can reverse direction.autoFocus={false}being ignored for modal popovers.z-indexon the positioner being ignoredwhen the content has no stacking level.
intercepting clicks.
formatOptionschanges to a subset of the previous options.onActiveChangereporting the previousactiveIdsandactiveItems, which kept a controlled TOCstuck on the old section.
replaced, and the backdrop leaving part of the page undimmed on resize.
derived_inertwarnings when a component's cleanup runs after it unmounts.and data URLs.
Illegal invocationthrown on setup when a tool like Storybook has replacedHTMLElement.prototype.focus.nuxt/nuxt (@nuxt/kit)
v4.6.0Compare Source
📣 Some news
🖥️ Nuxt CLI v4
Alongside the release of Nuxt v4.6, today also brings a new major release of the Nuxt CLI:
@nuxt/cliv4. It ships as a dependency ofnuxt, so you'll get it automatically when you upgrade.Most of what's new is in
nuxt dev:nuxt.configkeys changed, where the time went during a slow start or build, and how long each module took to set upmy-bad(see below), powering things like automatically reloading when a syntax error innuxt.config.tsis fixed.nuxt/, which lets a secondnuxt dev(say, one started by an agent) take over or defer to the one you started, and powers newnuxt curlandnuxt taskcommands that talk to the running serverThere's also a new
nuxt docs "<query>"search, andnuxt preview --takeovercan replace a running preview server. And in generalnuxt/cliis a lot smaller and starts a lot faster:@nuxt/cliinstall size@nuxt/clidependenciesnuxt dev: first paintnuxt dev: port boundnuxt dev: memory at rest (Linux)Although this is a major version, none of the changes should be breaking for Nuxt v4 users: we require Node.js v22.21+, v24.11+ or v26+, we drop
nuxt initand only supportnpm create nuxt@latest, and Nuxt 2 and@nuxt/bridgeare no longer supported.👉 Check out the full Nuxt CLI v4 release notes for everything that's changed.
💡 A server-agnostic Nuxt
The biggest thing about this release is our move towards making Nuxt server-agnostic.
I feel that freedom of choice is very much a fundamental value of the web, and one that unites the whole Nuxt team.
You can use
pages/(with vue-router) or not. You can use Vite, webpack or Rspack to bundle your code. You can pick from dozens of providers to deploy to, pick any image or font provider, choose any database adapter. In every case, the framework is the same.The server side was different.
#appcomposables imported h3 types, server code imported fromh3andnitropack, and every module that touched the server was tied to whichever major version of those packages Nuxt happened to depend on.This has become particularly clear as we have been upgrading to new majors of h3 and nitro, which ship breaking changes with a cascading effect throughout the whole ecosystem.
👉 This release changes that.
Alongside explicitly defining our public API in
nuxt/kit(which now does not refer to external packages), Nuxt now specifies our own types for the request event, route rules and typed$fetch, and we expose an import surface (nuxt/server) for the server utilities that will be needed by most apps.This is the culmination of work we started almost a year ago, making it possible to use any server builder with Nuxt, not just Nitro (#33462).
Of course, under the hood,
nuxt/serveris still powered by Nitro by default - though we are also announcing a second, experimental implementation,@nuxt/vite-server, which allows pure-Vite server builds using the Vite Environment API.🌟 We see a number of key benefits for
nuxt/server.nuxt/serveron 4.6 runs unchanged there, so a module can ship one file for both./appand/server- and the bundler + server that you ultimately want to build your app.... and there are a number of other benefits too, from a single type surface to being able to iterate more quickly on features.
Finally, I want to say a special thank-you to @pi0, whose relentless focus on server agnosticism and work on h3, Nitro and web-standard server primitives over the last few years is what makes a portable
RequestEventpossible at all. Thank you, Pooya. ❤️Almost every feature in this release is already in the Nuxt 5 branch, and most of the remaining Nuxt 5 defaults can be tested today with
future.compatibilityVersion: 5(more details below!).👀 Highlights
🤷 If you've read this far I'm afraid I have bad news for you: there's a lot more still to say! Nuxt 4.6 is one of our biggest minor releases, with over 420 commits since v4.5.2.
... so, you might want to grab a coffee! ☕️
🧩
nuxt/serverIt has been asked for for a long time, and it now exists (#36275)!
nuxt/serveris a new import source for server code: handlers, middleware and utilities - a complement tonuxt/app. Wherenuxt/appis for the part of your application that also runs in the browser,nuxt/serveris for the part that only runs on the server.The utilities use web standards and are typed against a portable
RequestEvent:Under
@nuxt/nitro-serverthey are backed by Nitro and h3, but you never import from either.So the same handler runs under Nitro v2, Nitro v3 or
@nuxt/vite-server, and a module that imports fromnuxt/serverdoesn't need a peer dependency onh3ornitropack.We think this will make a big difference in smoothing out the upgrade to Nuxt v5 and Nitro v3.
There is a typing benefit too. We no longer hoist h3 or Nitro types into your app to type
useRequestEvent,$fetchor route rules, which removes a source of type conflicts when versions differ (#36212, #36214, #36293).The surface is small, and covers what published modules and user code typically need:
defineEventHandler,createError/isNuxtError, request URL, headers, query, body (plain and validated with any Standard Schema library or a function), cookies, redirects, response status,getRouterParam(s),getRequestIP,handleCors,getRouteRules,useRuntimeConfig,useAppConfigand sessions.We encourage you to use web APIs (
event.req.headers, for example), or raise an issue if there's functionality you're missing fromnuxt/server🙏If you do need to step outside
nuxt/serverfor a particular handler, don't worry! Nothing has been taken away: importdefineEventHandlerand the helpers you need fromh3ornitropack/runtimeas before, and that handler works exactly as it did on Nuxt 4.5.A few helpers also behave differently from their h3 v1 namesakes:
sendRedirectreturns the response rather than sending it,createErrortakesstatusandstatusText, and response headers are set throughevent.res.headers. The upgrade guide has a table of the differences.Nothing in this release requires a migration. But if you have server code you'd like to make portable ahead of Nuxt 5, this is the best way.
👉 Read the server imports guide.
🔐
appSecretand sessionsNuxt now has a root application secret:
runtimeConfig.appSecret, set withNUXT_APP_SECRET(#35874, thanks to @onmax). Modules and server features derive purpose-specific secrets from it withderiveSecret(purpose), soNUXT_APP_SECRETis the only secret you need to configure.In development Nuxt generates and persists one if none is configured (and warns the first time a derived secret is used). Builds never generate one.
The first thing to use it is a set of session helpers in
nuxt/server(#36358). Sessions are sealed into a cookie with iron, so there's no server-side storage to configure:🎯 Typed
$fetch, rebuilt$fetchanduseFetchhave been typed from your server routes for a long time. But the types were derived from Nitro'sInternalApiinterface, and past a few hundred routes they hit TypeScript's instantiation limit with the familiarTS2589: Type instantiation is excessively deep and possibly infinite.We've rebuilt typed fetch on top of
fetchdts(#36238). Nuxt compiles your server routes into a route tree with an exact-match table for static paths and accessors specialised to your route set. Resolution cost now scales with call sites, not with route count:TS2589)TS2589)TS2589)Peak memory for the same runs dropped from 946 MB to 140 MB. 🔥
Plus, the route set also carries the
body,queryandheadersa handler validates, so calls are checked more tightly than before:On Nuxt 4 this is opt-in, because there are small changes to type inference, and hand-written
ServerRoutesaugmentations need a small rewrite. It is the default in Nuxt 5.There's also a new
experimental.strictRouteTypesoption to reject calls to paths that don't exist (otherwise these just returnunknown), and an'isomorphic'mode that types your pages asGETroutes too if you want to be able to$fetchfrom the Vue renderer with type safety.👉 Read more in the experimental features docs.
🐛 Better errors in development with
my-badServer-side errors in development used to look like this: