Skip to content

fix(deps): update root - #42

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/root
Open

fix(deps): update root#42
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/root

Conversation

@renovate

@renovate renovate Bot commented Jan 1, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@antfu/eslint-config 2.10.02.27.3 age confidence
@nuxt/kit (source) ^3.11.1^3.21.10 age confidence
@nuxt/module-builder ^0.5.5^0.8.4 age confidence
@nuxt/schema (source) ^3.11.1^3.21.10 age confidence
@nuxt/test-utils ^3.12.0^3.23.0 age confidence
@types/node (source) ^20.11.30^20.19.43 age confidence
@vitejs/plugin-vue (source) ^5.0.4^5.2.4 age confidence
@vitest/coverage-v8 (source) ^1.4.0^1.6.1 age confidence
bumpp ^9.4.0^9.11.1 age confidence
eslint (source) ^8.57.0^8.57.1 age confidence
lint-staged ^15.2.2^15.5.2 age confidence
playwright-core (source) ^1.42.1^1.62.1 age confidence
simple-git-hooks ^2.11.1^2.13.1 age confidence
typescript (source) ^5.4.3^5.9.3 age confidence
unconfig (source) ^0.3.11^0.6.1 age confidence
unplugin-vue-macros (source) ^2.7.13^2.14.5 age confidence
vue (source) ^3.4.21^3.5.40 age confidence

Release Notes

antfu/eslint-config (@​antfu/eslint-config)

v2.27.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.27.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.27.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.27.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.26.1

Compare Source

No significant changes

    View changes on GitHub

v2.26.0

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.25.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.25.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.25.0

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.24.1

Compare Source

   🚀 Features
    View changes on GitHub

v2.24.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.23.2

Compare Source

No significant changes

    View changes on GitHub

v2.23.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.23.0

Compare Source

   🚀 Features
  • Introduce type options, enable ts/explicit-function-return-type for lib  -  by @​antfu (3dd7b)
   🐞 Bug Fixes
    View changes on GitHub

v2.22.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.22.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.22.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.22.1

Compare Source

No significant changes

    View changes on GitHub

v2.22.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.21.3

Compare Source

No significant changes

    View changes on GitHub

v2.21.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.21.1

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.21.0

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.20.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.19.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.19.1

Compare Source

   🚀 Features
    View changes on GitHub

v2.19.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.18.1

Compare Source

   🚀 Features
    View changes on GitHub

v2.18.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.17.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.16.4

Compare Source

No significant changes

    View changes on GitHub

v2.16.3

Compare Source

   🚀 Features
    View changes on GitHub

v2.16.2

Compare Source

No significant changes

    View changes on GitHub

v2.16.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.16.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.15.0

Compare Source

   🚨 Breaking Changes
    View changes on GitHub

v2.14.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.13.4

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v2.13.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.13.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.13.1

Compare Source

   🚀 Features
    View changes on GitHub

v2.13.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.12.2

Compare Source

   🚀 Features
    View changes on GitHub

v2.12.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.12.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.11.6

Compare Source

   🚀 Features
    View changes on GitHub

v2.11.5

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.11.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v2.11.3

Compare Source

   🚀 Features
    View changes on GitHub

v2.11.2

Compare Source

No significant changes

    View changes on GitHub

v2.11.1

Compare Source

   🚀 Features
    View changes on GitHub

v2.11.0

Compare Source

   🚀 Features
    View changes on GitHub

v2.10.1

Compare Source

No significant changes

    View changes on GitHub
nuxt/nuxt (@​nuxt/kit)

v3.21.10

Compare Source

⚠️ This is a security release. We recommend upgrading as soon as possible with npx nuxt upgrade --dedupe.

It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.

If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.

Full details: Nuxt Security Patch Releases and GitHub Security Advisories.

👉 Changelog

compare changes

🩹 Fixes
  • nuxt: Clear hide/reset timeouts in set() (#​35534)
  • nuxt: Preserve trailing slash in NuxtLink href when unset (#​35501)
  • vite: Resolve SSR inlined CSS module class name mismatch (#​35610)
  • nuxt: Sync layout meta during middleware on SSR (#​35633)
  • nuxt: Update client URL to match SSR on fatal middleware error (#​35637)
  • nuxt: Watch external component directories in development (#​35652)
  • nuxt: Don't cross-pollute useAsyncData cache on reactive key change (#​35656)
  • nuxt: Return global route for useRoute in detached effect scope (#​35659)
  • nuxt: Ignore custom name or path when reusing an existing page in pages:extend (#​35661)
  • nuxt: Preserve explicit useFetch method inference (#​35671)
  • nuxt: Correct default export detection in plugin metadata (#​35676)
  • nuxt: Reload real page module on HMR of JSX render-function pages (#​35678)
  • vite: Ensure server sourcemap-preserver plugin actually runs (#​35680)
  • nuxt: Resolve @unhead/vue/* from nuxt's dependency tree (#​35690)
  • nuxt: Don't apply scroll behaviour after a subsequent nav (#​35719)
  • vite: Preserve css suffix when extracting ssr inline styles (#​35714)
  • nuxt: Don't exclude client entry module from style extraction (#​35720)
  • kit: Avoid mutating layer configs when resolving options (#​35729)
  • nuxt: Generate layout types even when pages module is disabled (#​35717)
  • nitro: Skip resource hints for stylesheets already rendered as blocking links (#​35691)
  • nuxt: Revalidate cached route payloads instead of using force-cache (#​35672)
  • nuxt: Preserve query params in cached payload extraction (#​35696)
  • rspack,webpack: Resolve loaders and runtime deps from nuxt dirs (#​35568)
  • nuxt: Render client components in nested server components (#​35669)
  • nuxt: Remove dev error overlay when error is cleared (#​35821)
  • rspack,webpack: Resolve bundled postcss defaults from builder (#​35823)
  • schema: Normalise slashes in app.buildAssetsDir (#​35833)
  • nuxt: Case-fold route rule keys to match folded lookups (619963309)
  • nitro: Require loopback peer for chrome devtools workspace endpoint (00f71bb65)
  • nitro: Bound island props and v-for to prevent unauthenticated DoS (668cdfdfd)
  • nuxt: Reject reserved template island prop under runtime compiler (5b60017f7)
  • nuxt: Reject top-level as prop for islands (00a2b0494)
📖 Documentation
  • Document relative baseURL workarounds (#​34004)
  • Warn about runtimeCompiler security best practices (b76c1a8bd)
  • Warn about validating server component props (f6d72628d)
✅ Tests
  • Guard against transient undefined _route in gotoPath (5391e7e6a)
  • Raise route-HMR polling timeout to reduce e2e flakiness (cbc757c63)
  • kit: Scope loadNuxt temp dir so it doesn't delete sibling fixtures (72e4b5578)
❤️ Contributors

v3.21.9

Compare Source

3.21.9 is the next patch release.

👉 Changelog

compare changes

🩹 Fixes
  • vite: Use spa entry for vite-node fallback (3.x) (c8410a16a)
  • kit,nuxt: Pass error as cause when we re-throw (#​35387)
  • vite: Inline CSS for lazy components imported from #components (#​35215)
  • nuxt: Validate <ClientOnly> fallback tag name (#​35325)
  • vite: Extract server page CSS when inlineStyles is disabled (#​35209)
  • nitro: Include nested layers in nitro transforms (#​35327)
  • nitro: Export empty styles object with ssr: false (#​35330)
  • nuxt: Emit auto-import paths as files, not directories (#​35333)
  • nuxt: Suppress spurious slot warning in NuxtPage during nav (#​35335)
  • vite: Preserve backslash separators in windows named pipe path (#​35336)
  • nuxt: Detach in-flight promise on useAsyncData teardown (#​35328)
  • nuxt: Respect per-page keepalive set via definePageMeta (#​34526)
  • nuxt: Align useFetch error type with runtime (#​35346)
  • nuxt: Unwrap getter body in useFetch (#​35343)
  • rspack,webpack: Strip invalid webpack PURE annotations (#​35386)
  • nuxt: Guard against -1 when unregistering a router hook (#​35391)
  • nuxt: Clean up load/error listeners in preloadPayload (#​35392)
  • nuxt: Avoid idle wait when refreshing data after hydration (#​35358)
  • nuxt: Ensure page:start finishes before page:finish starts (#​35408)
  • nuxt: Preserve plugin navigation during app boot (#​35344)
  • vite: Add extension to vite-node-runner virtual import (e81a0c484)
  • nuxt: Make virtual module IDs stable across hosts (#​35317)
  • nuxt: Hash serialized island props (#​35356)
  • vite: Avoid emitted ssr styles file name collisions (#​35432)
  • nuxt: Avoid syncing route too early when reused page remounts (#​35440)
  • nuxt: Keep nested layout on deferred route during suspended layout switch (#​35443)
  • vite: Set define for NODE_ENV and __VUE_PROD_DEVTOOLS__ (#​35444)
  • nuxt: Restore deferred query route before page is mounted (#​35442)
  • nuxt: Make islands hash backwards-compatible (#​35452)
  • nuxt: Pass nuxt rootDir to typed-router context (#​35565)
  • nitro: Only reload nitro after initial nitro build (6ba8e26a5)
  • schema: Enable HMR for defineNuxtComponent in JSX (#​35620)
  • schema: Resolve Vite cache directory from workspace (#​35626)
  • nitro: Write prerender cache files atomically (#​35619)
  • nuxt: Apply latest navigation on concurrent navigateTo in built-in router (#​35631)
📖 Documentation
  • Improving testing documentation for better understanding (#​35526)
  • Add tip about prerendering registration for pages (#​35635)
  • Clarify useFetch custom data error (#​35647)
  • Drop reference to non-existent section (bd1943d04)
  • Update link to /3.x slug (71bdb972d)
🏡 Chore
✅ Tests
  • Assert dev css delivery transport for server pages (9851e993b)
  • Count only render-blocking stylesheet links for page styles (b0e895a7f)
  • Await expectNoClientErrors (afffe7f09)
🤖 CI
  • Handle missing base branch (for stacked prs) (13a933f8a)
  • Unlink issues from autoclosed PRs (#​35615)
❤️ Contributors

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every 8 months on the first day of the month"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Jan 1, 2025
@renovate
renovate Bot force-pushed the renovate/root branch 4 times, most recently from 6cf4f5d to 0f2f8d9 Compare January 6, 2025 11:18
@renovate
renovate Bot force-pushed the renovate/root branch 8 times, most recently from 038f3f0 to f66baad Compare January 15, 2025 06:56
@renovate
renovate Bot force-pushed the renovate/root branch 9 times, most recently from 8db8172 to 52fb833 Compare January 22, 2025 11:40
@renovate
renovate Bot force-pushed the renovate/root branch 8 times, most recently from d1792a7 to 88bcb57 Compare January 29, 2025 11:25
@renovate
renovate Bot force-pushed the renovate/root branch 7 times, most recently from 5a9e73f to 4f4c4b2 Compare March 3, 2025 19:03
@renovate
renovate Bot force-pushed the renovate/root branch 5 times, most recently from 045d66d to 9ac72c2 Compare March 12, 2025 18:09
@renovate
renovate Bot force-pushed the renovate/root branch 6 times, most recently from fb2ce3c to 926c45e Compare March 21, 2025 14:16
@renovate
renovate Bot force-pushed the renovate/root branch 3 times, most recently from 4722f4f to ea42f6d Compare March 27, 2025 05:42
@renovate
renovate Bot force-pushed the renovate/root branch 4 times, most recently from ce19b60 to 4d9e0b7 Compare April 5, 2025 00:37
@renovate
renovate Bot force-pushed the renovate/root branch 2 times, most recently from 1657d0a to 28c6164 Compare April 17, 2025 18:12
@renovate
renovate Bot force-pushed the renovate/root branch 2 times, most recently from 7b4dd18 to fc4e59f Compare April 25, 2025 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants