Sourced from @nuxt/vite-builder's
releases.
v3.15.4
3.15.4 is the next patch release.
✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --forceThis will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
🩹 Fixes
- nuxt: Improve error logging when parsing with
acorn(#30754)- nuxt: Clear island uid before saving into the payload (#30767)
- kit: Load
@nuxt/schemafromnuxtpackage dir (#30774)- nuxt: Allow restarting nuxt on paths outside
srcDir(#30771)- nuxt: Don't warn about calling
useRoutein SFC setup (#30788)- webpack: Disallow cross-site requests in no-cors mode (#30757)
- vite: Restore
externalityfor dev server externals (#30802)💅 Refactors
- vite: Use new rollup
chunk.namesfor asset names (#30780)❤️ Contributors
- Daniel Roe (
@danielroe)- Peter Radko (
@Gwynerva)- Lansi (
@lansi951)- Julien Huang (
@huang-julien)- Norbiros (
@Norbiros)v3.15.3
3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99 and https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the
devServer.corsoptions in yournuxt.config, which may be relevant if you are developing with a custom hostname:export default defineNuxtConfig({ </tr></table>
... (truncated)
244da17
v3.15.456d889e
fix(vite): restore externality for dev server externals (#30802)325ed41
refactor(vite): use new rollup chunk.names for asset names
(#30780)940bcb8
chore(deps): update all non-major dependencies (3.x) (#30747)048f974
v3.15.3c6056bd
chore(deps): update all non-major dependencies (3.x) (#30733)406db5b
fix(vite,webpack): restrict access via cors to local origins + allow
configur...09d8db5
chore(deps): update vitest to v3.0.4 (3.x) (#30724)10a5495
fix(vite): inline shared folder in dev mode (#30690)f1c2948
chore(deps): update all non-major dependencies (3.x) (#30694)Sourced from nuxt's releases.
v3.15.4
3.15.4 is the next patch release.
✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --forceThis will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
🩹 Fixes
- nuxt: Improve error logging when parsing with
acorn(#30754)- nuxt: Clear island uid before saving into the payload (#30767)
- kit: Load
@nuxt/schemafromnuxtpackage dir (#30774)- nuxt: Allow restarting nuxt on paths outside
srcDir(#30771)- nuxt: Don't warn about calling
useRoutein SFC setup (#30788)- webpack: Disallow cross-site requests in no-cors mode (#30757)
- vite: Restore
externalityfor dev server externals (#30802)💅 Refactors
- vite: Use new rollup
chunk.namesfor asset names (#30780)❤️ Contributors
- Daniel Roe (
@danielroe)- Peter Radko (
@Gwynerva)- Lansi (
@lansi951)- Julien Huang (
@huang-julien)- Norbiros (
@Norbiros)v3.15.3
3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99 and https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the
devServer.corsoptions in yournuxt.config, which may be relevant if you are developing with a custom hostname:export default defineNuxtConfig({ </tr></table>
... (truncated)
244da17
v3.15.4ceaf0f5
chore(deps): update all non-major dependencies (3.x) (#30804)626eba0
fix(nuxt): don't warn about calling useRoute in SFC setup
(#30788)7a1e5c8
fix(nuxt): allow restarting nuxt on paths outside srcDir
(#30771)ca2d91f
fix(kit): load @nuxt/schema from nuxt package
dir (#30774)b78da56
fix(nuxt): clear island uid before saving into the payload (#30767)e0c47f9
fix(nuxt): improve error logging when parsing with acorn
(#30754)940bcb8
chore(deps): update all non-major dependencies (3.x) (#30747)048f974
v3.15.3e96a96d
perf(nuxt): enable Transition component only on client side
(#30720)Sourced from vite's releases.
v5.4.12
This version contains a breaking change due to security fixes. See https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6 for more details.
Please refer to CHANGELOG.md for details.
v5.4.11
Please refer to CHANGELOG.md for details.
v5.4.10
Please refer to CHANGELOG.md for details.
v5.4.9
Please refer to CHANGELOG.md for details.
v5.4.8
Please refer to CHANGELOG.md for details.
v5.4.7
Please refer to CHANGELOG.md for details.
v5.4.6
Please refer to CHANGELOG.md for details.
v5.4.5
Please refer to CHANGELOG.md for details.
v5.4.4
Please refer to CHANGELOG.md for details.
v5.4.3
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.3
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.2
Please refer to CHANGELOG.md for details.
v5.4.2
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.1
Please refer to CHANGELOG.md for details.
v5.4.1
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.0
Please refer to CHANGELOG.md for details.
... (truncated)
Sourced from vite's changelog.
5.4.12 (2025-01-20)
- fix!: check host header to prevent DNS rebinding attacks and introduce
server.allowedHosts(9da4abc)- fix!: default
server.cors: falseto disallow fetching from untrusted origins (dfea38f)- fix: verify token for HMR WebSocket connection (b71a5c8)
- chore: add deps update changelog (ecd2375)
5.4.11 (2024-11-11)
5.4.10 (2024-10-23)
- fix: backport #18367,augment hash for CSS files to prevent chromium erroring by loading previous fil (7d1a3bc), closes #18367 #18412
5.4.9 (2024-10-14)
- fix: bump launch-editor-middleware to v2.9.1 (#18348) (508d9ab), closes #18348
- fix(css): fix lightningcss dep url resolution with custom root (#18125) (eae00b5), closes #18125
- fix(data-uri): only match ids starting with
data:(#18241) (96084d6), closes #18241- fix(deps): bump tsconfck (#18322) (dc5434c), closes #18322
- fix(hmr): don't try to rewrite imports for direct CSS soft invalidation (#18252) (851b258), closes #18252
- fix(ssr): (backport #18150) fix source map remapping with multiple sources (#18204) (262a879), closes #18204
- chore: update all url references of vitejs.dev to vite.dev (#18276) (c23558a), closes #18276
- chore: update license copyright (#18278) (1864eb1), closes #18278
- docs: update homepage (#18274) (ae44163), closes #18274
5.4.8 (2024-09-25)
- fix(css): backport #18113, fix missing source file warning with sass modern api custom importer (#18 (7d47fc1), closes #18183
- fix(css): backport #18128, ensure sass compiler initialized only once (#18184) (8464d97), closes #18128 #18184
5.4.7 (2024-09-20)
5.4.6 (2024-09-16)
... (truncated)
f428aa9
release: v5.4.129da4abc
fix!: check host header to prevent DNS rebinding attacks and introduce
`serve...b71a5c8
fix: verify token for HMR WebSocket connectiondfea38f
fix!: default server.cors: false to disallow fetching from
untrusted originsecd2375
chore: add deps update changelogc54c860
release: v5.4.115f52bc8
release: v5.4.107d1a3bc
fix: backport #18367,augment
hash for CSS files to prevent chromium erroring ...898d61f
release: v5.4.9508d9ab
fix: bump launch-editor-middleware to v2.9.1 (#18348)Sourced from vite's releases.
v5.4.12
This version contains a breaking change due to security fixes. See https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6 for more details.
Please refer to CHANGELOG.md for details.
v5.4.11
Please refer to CHANGELOG.md for details.
v5.4.10
Please refer to CHANGELOG.md for details.
v5.4.9
Please refer to CHANGELOG.md for details.
v5.4.8
Please refer to CHANGELOG.md for details.
v5.4.7
Please refer to CHANGELOG.md for details.
v5.4.6
Please refer to CHANGELOG.md for details.
v5.4.5
Please refer to CHANGELOG.md for details.
v5.4.4
Please refer to CHANGELOG.md for details.
v5.4.3
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.3
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.2
Please refer to CHANGELOG.md for details.
v5.4.2
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.1
Please refer to CHANGELOG.md for details.
v5.4.1
Please refer to CHANGELOG.md for details.
plugin-legacy@5.4.0
Please refer to CHANGELOG.md for details.
... (truncated)
Sourced from vite's changelog.
5.4.12 (2025-01-20)
- fix!: check host header to prevent DNS rebinding attacks and introduce
server.allowedHosts(9da4abc)- fix!: default
server.cors: falseto disallow fetching from untrusted origins (dfea38f)- fix: verify token for HMR WebSocket connection (b71a5c8)
- chore: add deps update changelog (ecd2375)
5.4.11 (2024-11-11)
5.4.10 (2024-10-23)
- fix: backport #18367,augment hash for CSS files to prevent chromium erroring by loading previous fil (7d1a3bc), closes #18367 #18412
5.4.9 (2024-10-14)
- fix: bump launch-editor-middleware to v2.9.1 (#18348) (508d9ab), closes #18348
- fix(css): fix lightningcss dep url resolution with custom root (#18125) (eae00b5), closes #18125
- fix(data-uri): only match ids starting with
data:(#18241) (96084d6), closes #18241- fix(deps): bump tsconfck (#18322) (dc5434c), closes #18322
- fix(hmr): don't try to rewrite imports for direct CSS soft invalidation (#18252) (851b258), closes #18252
- fix(ssr): (backport #18150) fix source map remapping with multiple sources (#18204) (262a879), closes #18204
- chore: update all url references of vitejs.dev to vite.dev (#18276) (c23558a), closes #18276
- chore: update license copyright (#18278) (1864eb1), closes #18278
- docs: update homepage (#18274) (ae44163), closes #18274
5.4.8 (2024-09-25)
- fix(css): backport #18113, fix missing source file warning with sass modern api custom importer (#18 (7d47fc1), closes #18183
- fix(css): backport #18128, ensure sass compiler initialized only once (#18184) (8464d97), closes #18128 #18184
5.4.7 (2024-09-20)
5.4.6 (2024-09-16)
... (truncated)
f428aa9
release: v5.4.129da4abc
fix!: check host header to prevent DNS rebinding attacks and introduce
`serve...b71a5c8
fix: verify token for HMR WebSocket connectiondfea38f
fix!: default server.cors: false to disallow fetching from
untrusted originsecd2375
chore: add deps update changelogc54c860
release: v5.4.115f52bc8
release: v5.4.107d1a3bc
fix: backport #18367,augment
hash for CSS files to prevent chromium erroring ...898d61f
release: v5.4.9508d9ab
fix: bump launch-editor-middleware to v2.9.1 (#18348)