chore(deps): update nuxt framework to ^3.21.10 - #225
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
April 1, 2025 14:59
37ae8db to
a5d2758
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
April 28, 2025 01:12
a5d2758 to
e87f341
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
April 29, 2025 00:34
e87f341 to
f9d10ad
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
April 29, 2025 04:28
f9d10ad to
dc263ed
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
May 5, 2025 14:05
dc263ed to
8d9d834
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
May 12, 2025 14:59
8d9d834 to
f3e10d2
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
May 20, 2025 21:04
f3e10d2 to
323a28a
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
June 3, 2025 23:45
323a28a to
b450afa
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
July 1, 2025 18:42
b450afa to
6a0db8f
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
July 13, 2025 19:48
6a0db8f to
9314596
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
July 29, 2025 04:15
9314596 to
2241016
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
August 5, 2025 10:57
2241016 to
8e0af27
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
August 13, 2025 13:02
1647845 to
911e261
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
August 19, 2025 11:27
911e261 to
bf30ca6
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
September 3, 2025 02:33
6874d60 to
611c7ac
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
October 28, 2025 16:37
e26a28e to
3459427
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
November 7, 2025 04:38
3459427 to
43231a0
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
November 10, 2025 22:09
43231a0 to
bd8cdd0
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
November 18, 2025 23:09
bd8cdd0 to
55ab99f
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
December 9, 2025 17:50
f5c5652 to
8c0fbfa
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
December 31, 2025 18:10
8c0fbfa to
2c6d860
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
January 8, 2026 20:52
2c6d860 to
f69a153
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
January 23, 2026 02:32
bf079fe to
0340df8
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
January 23, 2026 21:11
0340df8 to
ba98b44
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
February 7, 2026 18:28
742b58d to
6e1827e
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
February 17, 2026 18:00
4bf5025 to
8672d74
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
2 times, most recently
from
March 12, 2026 15:07
baf61df to
46a778f
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
March 13, 2026 12:54
46a778f to
24a4b52
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
3 times, most recently
from
April 1, 2026 21:44
6801be4 to
4969bb7
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
April 8, 2026 15:32
4969bb7 to
90c9cd8
Compare
renovate
Bot
force-pushed
the
renovate/nuxt
branch
from
April 27, 2026 16:35
90c9cd8 to
e5b3747
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.7.0→^3.21.103.0.0-rc.4→3.21.10Release Notes
nuxt/nuxt (@nuxt/kit)
v3.21.10Compare Source
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, and dev server path disclosure. Refreshing your lockfile also pulls in
@nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
compare changes
🩹 Fixes
useRoutein detached effect scope (#35659)nameorpathwhen reusing an existing page inpages:extend(#35661)useFetchmethod inference (#35671)@unhead/vue/*from nuxt's dependency tree (#35690)force-cache(#35672)app.buildAssetsDir(#35833)templateisland prop under runtime compiler (5b60017f7)asprop for islands (00a2b0494)📖 Documentation
runtimeCompilersecurity best practices (b76c1a8bd)✅ Tests
_routein gotoPath (5391e7e6a)❤️ Contributors
v3.21.9Compare Source
👉 Changelog
compare changes
🩹 Fixes
causewhen we re-throw (#35387)#components(#35215)<ClientOnly>fallback tag name (#35325)inlineStylesis disabled (#35209)ssr: false(#35330)NuxtPageduring nav (#35335)useAsyncDatateardown (#35328)definePageMeta(#34526)bodyinuseFetch(#35343)page:startfinishes beforepage:finishstarts (#35408)NODE_ENVand__VUE_PROD_DEVTOOLS__(#35444)rootDirto typed-router context (#35565)navigateToin built-in router (#35631)📖 Documentation
🏡 Chore
✅ Tests
expectNoClientErrors(afffe7f09)🤖 CI
❤️ Contributors
v3.21.8Compare Source
👉 Changelog
compare changes
🩹 Fixes
typeoption infindPath(#35272)📖 Documentation
nulltoundefinedin data-fetching docs to match actual types (#35301)❤️ Contributors
v3.21.7Compare Source
👉 make sure to check https://github.com/nuxt/nuxt/security/advisories to view open advisories resolved by this release.
👉 Changelog
compare changes
🩹 Fixes
noSSRbefore deciding payload extraction (#35108)allowDirs(#35112)pathefor buildCache path boundary check (#35111)isValidin dev clipboard-copy listener (#35109)reloadNuxtApppath before reload (#35115)clientServerwithssr: false(#34959).d.mts/.d.ctsinresolveTypePaths(#35235)<NuxtClientFallback>ssr output (#35199)isScriptProtocolguard tonavigateToopen option (#35206)defuin app config template (40bedf0db)vue-router(3f3e3fa7b)<NoScript>slot content (7fea9fd68)navigateTo(1f2dd5e78)reloadNuxtApp(6497d99dd)<NuxtLink>href (53284043d)defu(d11d7b1b5)📖 Documentation
🏡 Chore
execFileSyncfor safety in release scripts (9a455a658)✅ Tests
🤖 CI
❤️ Contributors
v3.21.6Compare Source
👉 Changelog
compare changes
🩹 Fixes
setPageLayoutprops on same-path navigation (#35055)useLoadingIndicatorproperties as readonly (#35062)statusCodefor nitro v2 compatibility (82dcd6a31)💅 Refactors
📖 Documentation
🏡 Chore
✅ Tests
app/(6d2ac69ff)🤖 CI
test:enginesfails (958abb882)❤️ Contributors
v3.21.5Compare Source
👉 Changelog
compare changes
🔥 Performance
isIgnoredrelative (#35015)🩹 Fixes
/+ overridessr: true(#34990).envbefore resolving nuxt schema (#34958)serverHandlersarray afternitro:config(#34985)📖 Documentation
🏡 Chore
✅ Tests
buildDirper matrix project for shared fixtures (#35007)❤️ Contributors
v3.21.4Compare Source
v3.21.2Compare Source
v3.21.1Compare Source
👉 Changelog
compare changes
🩹 Fixes
server/forbuilder:watchhook (#34208)x-nitro-prerenderheader (#34202)error.messagefor fatal errors (#34226)#appbarrel export in keyed functions (#34199)datetime in` (#33992)nuxt/schema(#34255)meta.name(#34263)#componentsimport mapping conflict for packages outside rootDir (#34139)nuxt/schemaonce more (9f5bb611d)💅 Refactors
genObjectKeyto omit unnecessary quotes (#34245)ComponentPropshelper to extract layout props (#34248)📖 Documentation
keyedComposables(#34201)🏡 Chore
pxfromwidthattribute (e80147f7d)✅ Tests
<NuxtPage>navigation (707a9dc44)❤️ Contributors
v3.21.0Compare Source
Nuxt 4.3 and 3.21 bring powerful new features for layouts, caching, and developer experience – plus significant performance improvements under the hood.
📣 Some News
Extended v3 Support
Early this month, I opened a discussion to find out how the upgrade had gone from v3 to v4. I was really pleased to hear how well it had gone for most people.
Having said that, we're committed to making sure no one gets left behind. And so we will continue to provide security updates and critical bug fix releases beyond the previously announced end-of-life date of January 31, 2026, meaning Nuxt v3 will meet its end-of-life on July 31, 2026.
Preparing for Nuxt 5
We're closer than ever to the releases of Nuxt v5 and Nitro v3. In the coming weeks, the
mainbranch of the Nuxt repository will begin receiving initial commits for Nuxt 5. However, it's still business as usual.mainbranch4.xand3.xbranchesKeep an eye out on the Upgrade Guide – we'll be adding details about how you can already start migrating your projects to prepare for Nuxt v4 with
future.compatibilityVersion: 5.🗂️ Route Rule Layouts
But that's enough about the future. We have a lot of good things for you today!
First, you can now set layouts directly in route rules using the new
appLayoutproperty (#31092). This provides a centralized, declarative way to manage layouts across your application without scatteringdefinePageMetacalls throughout your pages.This might be useful for:
📦 ISR/SWR Payload Extraction
Payload extraction now works with ISR (incremental static regeneration), SWR (stale-while-revalidate) and cache
routeRules(#33467). Previously, only pre-rendered pages could generate_payload.jsonfiles.This means:
🧹 Dev Mode Payload Extraction
Related to the above, payload extraction now also works in development mode (#30784). This makes it easier to test and debug payload behavior without needing to run a production build.
🚫 Disable Modules from Layers
When extending Nuxt layers, you can now disable specific modules that you don't need (#33883). Just pass
falseto the module's options:🏷️ Route Groups in Page Meta
Route groups (folders wrapped in parentheses like
(protected)/) are now exposed in page meta (#33460). This makes it easy to check which groups a route belongs to in middleware or anywhere you have access to the route.This provides a clean, convention-based approach to route-level authorization without needing to add
definePageMetato every protected page.🎨 Layout Props with
setPageLayoutThe
setPageLayoutcomposable now accepts a second parameter to pass props to your layout (#33805):🔧
#serverAliasA new
#serveralias provides clean imports within your server directory (#33870), similar to how#sharedworks:The alias includes import protection – you can't accidentally import
#servercode from client or shared contexts.🪟 Draggable Error Overlay
The development error overlay introduced in Nuxt 4.2 is now draggable and can be minimized (#33695). You can:
This is a quality-of-life improvement when you're iterating on fixes and don't want the overlay blocking your view.
https://github.com/user-attachments/assets/nuxt_4-3_error_demo.mp4
⚙️ Async Plugin Constructors
Module authors can now use async functions when adding build plugins (#33619):
This enables true lazy loading of build plugins, avoiding unnecessary code loading when plugins aren't needed.
🚀 Performance Improvements
This release includes several performance optimizations for faster builds:
nuxt:ssr-stylesplugin is now significantly faster (#33862, #33865)rou3, removing the need forradix3in the client bundle and eliminating app manifest fetches (#33920)🎨 Inline Styles for Webpack/Rspack
The
inlineStylesfeature now works with webpack and rspack builders (#33966), not just Vite. This enables critical CSS inlining for better Core Web Vitals regardless of your bundler choice.statusCode→status,statusMessage→statusTextIn preparation for Nitro v3 and H3 v2, we're moving to use Web API naming conventions (#33912). The old properties still work but are deprecated in advance of v5:
🐛 Bug Fixes
Notable fixes in this release:
keyattribute (#33958, #33963)useCookieunsafe number parsing during decode (#34007)NuxtPagenot re-rendering when nestedNuxtLayouthas layouts disabled (#34078)allowArbitraryExtensionsby default in TypeScript config (#34084)noUncheckedIndexedAccessto server tsconfig for safer typing (#33985)📚 Documentation
🎉 Nuxt 3.21.0
Alongside v4.3.0, we're releasing Nuxt v3.21.0 with many of the same improvements backported to the 3.x branch. This release includes:
setPageLayout,#serveralias, draggable error overlay, and morefalseuseCookienumber parsing, head component deduplication, and more✅ Upgrading
Our recommendation for upgrading is to run:
This will deduplicate your lockfile and help ensure you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
compare changes
🚀 Enhancements
#serveralias for server directory imports (#33870)crosswstypes (6ff79ea6c)false(#33883)moduleDependenciesas an async function (#33504)appLayoutin route rules (#31092)setPageLayout(#33805)🔥 Performance
nuxt:ssr-stylesplugin (#33862)🩹 Fixes
router.replacein page hmr (#33897)page:loading:endin cache if already called (fbbe10133)NUXT_VITE_NODE_OPTIONS(8abb7ef5b)appMiddlewarereferences invalid key (ed8bb68c5)nuxt/meta(b748840bc)keyfor tag deduplication in<Head>component (#33958)build.transpilewhen initialising vite (#33868)onUpgradearguments with types (#33988)rou3(7da94e8c3)noUncheckedIndexedAccessto server tsconfig (#33985)useRequestFetch(#33976)h3typesConfiguration
📅 Schedule: (UTC)
* * * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.