chore(deps): update nuxt core - #1500
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
✅ Deploy Preview for nuxt-sanity-module ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
commit: |
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
July 19, 2026 20:19
57ce361 to
411eff2
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
August 8, 2026 19:00
411eff2 to
3d2bb49
Compare
danielroe
approved these changes
Aug 8, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Aug 8, 2026
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
August 8, 2026 19:35
3d2bb49 to
e136203
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.35.2→3.37.04.5.0→4.5.21.0.2→1.0.34.4.7→4.5.24.0.3→4.1.04.4.7→4.5.23.5.40→3.5.41Release Notes
nuxt/cli (@nuxt/cli)
v3.37.0Compare Source
👉 Changelog
compare changes
🚀 Enhancements
nubpackage manager (#1360)🤖 CI
7fc085b)18b4417)❤️ Contributors
v3.36.1Compare Source
👉 Changelog
compare changes
🩹 Fixes
server.ws(vite 8.1+) (#1355)❤️ Contributors
v3.36.0Compare Source
👉 Changelog
compare changes
🚀 Enhancements
aube(#1348)vue-tscandtypescript(#1316)🩹 Fixes
nuxt.configfiles (#1345)ee31f82)✅ Tests
2b179ca)🤖 CI
f123be8)🎉 New Contributors
❤️ Contributors
nuxt/nuxt (@nuxt/kit)
v4.5.2Compare Source
👉 Changelog
compare changes
🔥 Performance
🩹 Fixes
v-forislands transform (#35877)applyandapplyToEnvironmentin vite wrapper (#35899)enforcein vite wrapper (#35916)vite-node(#35758)<NuxtPage>on nav + with slot (#35948)prependis set (#35942)import.meta.testfor server code (#35987)💅 Refactors
vue-component-type-helpersinstead of locally maintained helpers (#35840)isReferenceIdentifierin page-meta plugin (#35882)📖 Documentation
defineVitestProjectin e2e tests (#35926)📦 Build
🏡 Chore
@nuxt/devtoolsto v3.4.0 (#35892)✅ Tests
toFsUrl(a5ad667f7)🤖 CI
permissions: {}to workflows (2e1a1cbeb)❤️ Contributors
v4.5.1Compare Source
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in
@nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the
cache,swrorisrroute rules, purge any CDN or edge cache after upgrading; a leaked_payload.jsonmay already be cached upstream.Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
compare changes
🔥 Performance
vue.optionsApiand disable it for v5+ (#35791)ssr: false(#35782)🩹 Fixes
useRoutein detached effect scope (#35659)nameorpathwhen reusing an existing page inpages:extend(#35661)useFetchmethod inference (#35671)force-cache(#35672).mtsfile extension in resolver (#33845)@unhead/vue/*from nuxt's dependency tree (#35690)$fetchwith nitro's$Fetch(#35704)vue-routerwhen there are island pages (#35739)h3that pins it to the version nuxt depends on (#35774)fromcannot be resolved (#35799)app.buildAssetsDir(#35833)templateisland prop under runtime compiler (ee6c84633)asprop for islands (581651ff3)💅 Refactors
semverwithverkit(#35713)📖 Documentation
codeSplitting: false(#35683)onPrehydrateexample comment (#35684)runtimeConfigenv var casting edge cases (#35709)nuxtrather thannuxi(8891e179c)runtimeCompilersecurity best practices (449b63ab1)📦 Build
.tsfile extension fromruntime/imports (#35689)🏡 Chore
@nuxt/telemetryin knip (9824d4f10)@nuxt/devtoolsto v3.3.1 (#35815)✅ Tests
_routein gotoPath (ca92d082b)🤖 CI
knipjob (58f68bd64)❤️ Contributors
nuxt/module-builder (@nuxt/module-builder)
v1.0.3Compare Source
👉 Changelog
compare changes
🩹 Fixes
📦 Build
🏡 Chore
resolutions/pnpm.overridestopnpm-workspace.yaml(cfb45fb)afcf2fa)aeb1d38)92eb2af)✅ Tests
809c89f)9412c91)#appornuxt/appin generated declarations (#727)🤖 CI
604d5b3)4442a14)f7be1a6)reproduction(57e7ce9)c3c8e72)d87d217)54c5f13)🎉 New Contributors
❤️ Contributors
nuxt/test-utils (@nuxt/test-utils)
v4.1.0Compare Source
👉 Changelog
compare changes
🚀 Enhancements
🩹 Fixes
RouterLinkstub works withpages: false(#1687)ssr.resolve.conditionsto removeimport(#1732)defineVitestProject(#1724)viteEnvironmentApi(#1708)📦 Build
🏡 Chore
h3-nextto optional dependencies (#1733)✅ Tests
autoImport: false(#1688)🤖 CI
❤️ Contributors
vuejs/core (vue)
v3.5.41Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.