chore(deps): update dependency nuxt to v4 - #477
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
August 26, 2023 02:55
f4ddcf0 to
713e943
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
September 5, 2023 16:44
713e943 to
bb5e8c7
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
September 13, 2023 23:26
a65cccd to
c28cb5c
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
September 26, 2023 00:55
c28cb5c to
7c9dc06
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
October 19, 2023 21:05
7c9dc06 to
ab34f1a
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
November 6, 2023 16:27
ab34f1a to
3610072
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
November 21, 2023 00:12
3610072 to
318cb81
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
December 25, 2023 18:57
318cb81 to
4c2ae6e
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
January 6, 2024 02:14
4c2ae6e to
e40e93f
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
January 17, 2024 14:29
803ef22 to
246bd4e
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
February 5, 2024 19:16
97bba62 to
3968db6
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
February 14, 2024 15:01
3968db6 to
c577608
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
February 22, 2024 15:30
c577608 to
882eeee
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
March 18, 2024 22:47
0df1197 to
4322c0f
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
April 4, 2024 17:01
4322c0f to
a7c4bfd
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
3 times, most recently
from
June 16, 2024 10:16
c3bf33f to
5df2aff
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
July 5, 2024 22:51
5df2aff to
4e5e282
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
July 19, 2024 01:00
4e5e282 to
728bbb6
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
August 22, 2024 17:06
728bbb6 to
0174826
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
September 4, 2024 11:42
0174826 to
04eb632
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
September 16, 2024 00:53
04eb632 to
ad46566
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
November 6, 2024 13:43
f2097d3 to
0ddddd9
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
November 19, 2024 21:40
0ddddd9 to
f81341f
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
May 12, 2025 14:31
688979a to
6fb4ab9
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
May 20, 2025 21:51
6fb4ab9 to
414ed04
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
June 3, 2025 22:55
414ed04 to
dcc09c9
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
July 1, 2025 21:33
dcc09c9 to
3726e4a
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
July 16, 2025 01:02
65c7378 to
af5aaee
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
July 21, 2025 09:39
af5aaee to
414e175
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
July 29, 2025 00:57
414e175 to
fc2ede2
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
August 10, 2025 15:52
e34c9c4 to
af2f085
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
August 19, 2025 11:43
925c866 to
31a24e2
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
3 times, most recently
from
September 6, 2025 02:53
711097d to
f13284c
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
September 13, 2025 17:04
f13284c to
b9812eb
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
September 25, 2025 18:06
b9812eb to
7e1eaa0
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
October 6, 2025 19:14
7e1eaa0 to
4aa6c34
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
October 25, 2025 06:50
fe64049 to
6ad3e0c
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
November 10, 2025 22:49
33ddb65 to
590cb25
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
November 18, 2025 23:11
590cb25 to
5d1b404
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
2 times, most recently
from
December 9, 2025 17:50
e725f01 to
3613e92
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
December 31, 2025 17:54
3613e92 to
84dd161
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
January 8, 2026 20:53
84dd161 to
614f9e5
Compare
renovate
Bot
force-pushed
the
renovate/major-nuxtjs-monorepo
branch
from
January 19, 2026 17:10
614f9e5 to
dac75bd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.16.3→4.5.2Release Notes
nuxt/nuxt (nuxt)
v4.5.2Compare Source
👉 Changelog
compare changes
🔥 Performance
🩹 Fixes
v-forislands transform (#35877)applyandapplyToEnvironmentin vite wrapper (#35899)enforcein vite wrapper (#35916)vite-node(#35758)<NuxtPage>on nav + with slot (#35948)prependis set (#35942)import.meta.testfor server code (#35987)💅 Refactors
vue-component-type-helpersinstead of locally maintained helpers (#35840)isReferenceIdentifierin page-meta plugin (#35882)📖 Documentation
defineVitestProjectin e2e tests (#35926)📦 Build
🏡 Chore
@nuxt/devtoolsto v3.4.0 (#35892)✅ Tests
toFsUrl(a5ad667f7)🤖 CI
permissions: {}to workflows (2e1a1cbeb)❤️ Contributors
v4.5.1Compare Source
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in
@nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the
cache,swrorisrroute rules, purge any CDN or edge cache after upgrading; a leaked_payload.jsonmay already be cached upstream.Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
compare changes
🔥 Performance
vue.optionsApiand disable it for v5+ (#35791)ssr: false(#35782)🩹 Fixes
useRoutein detached effect scope (#35659)nameorpathwhen reusing an existing page inpages:extend(#35661)useFetchmethod inference (#35671)force-cache(#35672).mtsfile extension in resolver (#33845)@unhead/vue/*from nuxt's dependency tree (#35690)$fetchwith nitro's$Fetch(#35704)vue-routerwhen there are island pages (#35739)h3that pins it to the version nuxt depends on (#35774)fromcannot be resolved (#35799)app.buildAssetsDir(#35833)templateisland prop under runtime compiler (ee6c84633)asprop for islands (581651ff3)💅 Refactors
semverwithverkit(#35713)📖 Documentation
codeSplitting: false(#35683)onPrehydrateexample comment (#35684)runtimeConfigenv var casting edge cases (#35709)nuxtrather thannuxi(8891e179c)runtimeCompilersecurity best practices (449b63ab1)📦 Build
.tsfile extension fromruntime/imports (#35689)🏡 Chore
@nuxt/telemetryin knip (9824d4f10)@nuxt/devtoolsto v3.3.1 (#35815)✅ Tests
_routein gotoPath (ca92d082b)🤖 CI
knipjob (58f68bd64)❤️ Contributors
v4.5.0Compare Source
📣 Some News
Preparing for Nuxt 5
A good chunk of this release is (hopefully) invisible plumbing for Nuxt 5. We've moved onto the latest major versions of several core dependencies (
unheadv3,unctxv3, and Vite 8), switched the framework's own build over totsdown, and introduced a stablenuxt/*build output contract with dev exports so that type-checking in the Nuxt monorepo works without a build step (#35463, #35605).Much of this is working to shrink the gap between v4 and v5 internally, so that the migration will be as boring as possible.
With the release of Nuxt v4.5, our focus as a team will turn to stabilising Nuxt v5 and creating compatibility utilities to make the upgrade as smooth as possible.
Nuxt 3 End-of-Life
Nuxt 3 reaches end-of-life on July 31, 2026, so this is one of the last few 3.x releases we'll ship. If you're still on v3, now is a great time to move across. Most people told us the v3 to v4 upgrade was smooth, and we've kept the upgrade guide up to date.
Alongside v4.5.0 we're publishing a maintenance patch for the 3.x line (v3.21.9) with the compatible bug fixes and smaller improvements from this release backported. The headline items here (Vite 8, Rspack 2,
unheadv3,unctxv3) are major upgrades and stay v4-only, so 3.x remains stable as it approaches end-of-life.👀 Highlights
Nuxt 4.5 is a big one. This release ships three major upgrades to the build layer (Vite 8, Rspack 2, and a brand new Rsbuild-powered pipeline for the Rspack builder), an experimental SSR streaming mode, a handful of new composables and conventions, and a lot of groundwork that brings us closer to Nuxt 5.
There's a lot here, so grab a coffee. ☕️
⚡️ Vite 8
Nuxt now runs on Vite 8 (#34256). This brings faster cold starts, the latest Rolldown-powered internals, and many upstream improvements from the Vite team.
For most apps this is a transparent upgrade. If you have custom Vite plugins or config, it's worth skimming the Vite migration guide to check for anything that affects you.
🦀 Rspack 2 and Rsbuild
If you use the Rspack builder, this release is a substantial upgrade. We've moved to Rspack 2 (#34929), which is faster and lighter, and rebuilt the builder on top of
@rsbuild/core(#35489).The public surface stays the same. You still opt in with
builder: 'rspack'and the existingrspack:*hooks continue to work:Under the hood, though, a lot has changed for the better:
webpack-dev-middlewareandwebpack-hot-middleware(#35575).🌊 Experimental SSR Streaming
This is one I'm particularly excited about. You can now enable SSR streaming to dramatically improve Time to First Byte (#34411). Instead of buffering the whole rendered page and sending it in one go, Nuxt flushes the HTML shell (your
<head>, styles, preload hints, and entry scripts) immediately, then streams the body as Vue renders it.Streaming is automatically disabled for bots and crawlers so search engines still receive fully-rendered HTML. You can tune which user agents count as crawlers, and you can opt individual routes out:
There's one thing worth understanding before you turn it on. Because streaming commits the HTTP status and headers with the very first byte, anything that mutates the response after rendering has begun (a
setResponseStatus()in a<script setup>, a cookie write during middleware, and so on) can't reach the client. Nuxt handles the common cases for you: routes withredirect,cache,isr,swr,noScripts, orssr: falserules automatically fall back to the buffered renderer, and in development we log a warning naming any dropped mutations so nothing fails silently.📖 SSR streaming documentation
🩺 Stable Error Codes
This one I'm really happy about. Nuxt now has a stable error code system (#35429). Warnings and errors raised during build and at runtime now carry a stable code (like
NUXT_E1001orNUXT_B5001), a short explanation of why it happened, and a concrete fix to try.Every code is greppable and bookmarkable, and the ones that need more than a one-line fix link straight to a dedicated docs page. For example, the classic "a composable was called outside a Nuxt context" now surfaces as
NUXT_E1001with the why/fix inline and a docs page explaining the context rules and how to userunWithContext().To keep production output lean, the verbose why/fix text is stripped from production builds, leaving just the stable code.
This is the foundation for much better error messages across Nuxt, and we'll keep migrating existing warnings and errors onto it over the coming releases. If you've ever squinted at a cryptic Nuxt message, this is for you.
🎨
useLayoutComposableThere's a new
useLayoutcomposable for reading the layout that's been resolved for the current route (#35623). Previously there was no clean, reactive way to ask "which layout is this page using?" from within a component.It returns a read-only computed ref, so it stays in sync as you navigate or as route rules and
definePageMetachange the resolved layout.📖
useLayoutdocumentation🪟 Named Views
Nuxt now supports named views through a filename convention (#35123). If a parent page renders more than one
<NuxtPage>outlet, you can give each outlet a name and provide a sibling page file for it using thename@view.vueconvention:Navigating to
/parent/childrenderschild.vueinto the default outlet andchild@sidebar.vueinto thesidebaroutlet. This has actually been possible in Vue Router for a long time; this release wires it up to Nuxt's file-based routing.📖 Named views documentation
🚦
enabledOption foruseFetchanduseAsyncDataYou can now gate data fetching with a reactive
enabledoption (#33260). Whileenabledisfalse, every execution is blocked (the initial fetch,execute/refresh, and watch triggers), and if you flip it fromtruetofalsemid-flight, the in-flight request is cancelled without clearing your existingdata.This is perfect for dependent or conditional queries, where you don't want to fire a request until some precondition is met. It pairs naturally with a getter or a ref, so it stays reactive.
📖
useAsyncDatadocumentation🔗
NuxtLinkPrefetch Control for Custom SlotsWhen you use
<NuxtLink>with thecustomprop, Nuxt no longer attaches prefetch handlers for you, because it can't know how you've structured your markup. To make that ergonomic, the slot now exposes everything you need to wire prefetching up yourself (#34539):You get
prefetchto trigger it,prefetchedto know whether it's already happened (great for a prefetched class), andshouldPrefetchto respect the user's connection and config.📖
NuxtLinkdocumentation⚡️ Forwarded Preload Hints on Prefetch
Here's another one we'd love you to try. When you prefetch a link to a route with payload extraction, Nuxt already primes the destination's data and chunks. With the new opt-in
experimental.prefetchPreloadTags(#35144), it also forwards the destination's<link rel="preload">andmodulepreloadhints (whatever the page sets viauseHead, or via modules like@nuxt/image's<NuxtImg preload>) into the current document, downgraded torel="prefetch"so they don't compete with the resources the user is looking at right now.The practical effect is that heavy above-the-fold assets on the next page (a hero image, a critical script) start downloading while the user is still on the current one, so the navigation feels instant. It's off by default while we gather feedback, so please give it a spin and tell us how it behaves on your app.
🌐
import.meta.envNameThe resolved Nuxt environment name is now available at runtime as
import.meta.envNamefor both Vite and webpack/Rspack builds (#34844). This is the value set by--envName(or the resolved default), so you can branch on it in your app code:📖
import.metadocumentation🔭 Tracing Channels for SSR Events
Nuxt now publishes diagnostics-channel traces for its server-side subsystems (#35191). It's unopinionated: we emit
nuxt.render,nuxt.island,nuxt.data, andnuxt.pluginchannels following the untracing naming convention, and you can build OpenTelemetry (or anything else) on top. It works in Node, Deno, Bun, and Cloudflare Workers.You can also enable it granularly. In Nuxt v5, there will be additional Nitro-level channels:
📦 Dependency Upgrades
unheadv3Nuxt's head management now runs on
unheadv3 (#34793). It's smaller, uses a synchronous engine internally, and ships better type-safety foruseHeadout of the box. This also unblocks SSR streaming.unctxv3We've moved to
unctxv3 (#35541), which resolves a class of long-standing async context issues (#33644). This is part of the composable-context reliability work that continues into v5.And more
We've also updated
magic-stringto v1, Babel to v8, and pulled in the latest Rolldown across the board. Runningnuxt upgrade --dedupe(see below) is the easiest way to pull these through cleanly.🛠️ Nuxt CLI
This release bundles some improvements from
@nuxt/cliv3.36 and v3.37:nuxt module removeto uninstall a module and clean up its config (nuxt/cli#1306), the natural companion tonuxt module add.Non-interactive
nuxt initfor scripting and CI (nuxt/cli#1341), plus it now respects the template's own package manager instead of prompting (nuxt/cli#1330).Type-check onboarding:
nuxt typechecknow offers to installvue-tscandtypescriptfor you if they're missing (nuxt/cli#1316).Golar support for type-checking:
nuxt typecheckcan now use Golar as an alternative tovue-tsc(nuxt/cli#1362). It's picked up automatically if it's installed (or agolar.config.*file exists), and you can force a checker with--checker=vue-tscor--checker=golar:Layer-aware dev server: the dev server now reloads on changes to local layer
nuxt.configfiles (nuxt/cli#1345).🧩 TypeScript Plugin and Named Layout Slots
Nuxt's experimental TypeScript plugin is powered by
@dxup/nuxt, and this release bundles a newer version of it. If you haven't tried it, turning onexperimental.typescriptPlugingives you a set of editor niceties: renaming an auto-imported component updates every usage, plus go-to-definition for glob imports, Nitro routes,definePageMeta,runtimeConfig, and typed route names.New in the bundled version is an opt-in runtime feature: named layout slots (KazariEX/dxup#20). You can write a top-level named-slot template in a page and have it forwarded into the matching named slot of the active layout. That lets a page inject content into its layout's slots, which file-based layouts don't otherwise allow.
Enable it alongside the plugin:
Then a layout can expose named slots:
And any page using that layout can fill them:
📖
typescriptPlugindocumentation🔥 Performance and Reliability
As always, a lot of work has gone into making Nuxt faster and steadier.
One you can opt into today is the shared file watcher (#35143). Vite already runs a chokidar-based watcher, so Nuxt can piggy-back on it instead of spinning up a second one, using less memory and fewer file handles. This becomes the default with
compatibilityVersion: 5, but you can turn it on now and let us know how it goes:There are also some other good performance improvements that don't need to be opted into:
getIslandHashandhashKeynow exposed (#35583).A couple of other nice quality-of-life fixes:
$fetchis now auto-imported in user code, which fixes edge cases with top-level$fetch.createunder Rolldown's output format (#35581).HTTP_PROXY/HTTPS_PROXYenvironment variables in the builder environment (#35183).defineNuxtComponentin JSX (#35620).As mentioned above, this release includes three major dependency bumps. For most apps they're transparent, but they're worth a moment of attention:
builder: 'rspack', the internals are now Rsbuild-based, so custom Rspack config may need review.unheadv3: possible breaking type changes from stricteruseHeadtyping.⬆️ Upgrading
Our recommendation for upgrading is to run:
npx nuxt upgrade --dedupe # or, if you are staying on the 3.x line npx nuxt@latest upgrade --dedupe --channel=v3This will deduplicate your lockfile and help ensure you pull in updates from the other dependencies Nuxt relies on, particularly across the unjs ecosystem (which matters more than usual this release, given the major bumps).
Thank you to all of the many contributors to this release. This was a big one, and it wouldn't happen without you. 💚
👉 Changelog
compare changes
🚀 Enhancements
import.meta(#34844)allowImportingTsExtensions(87c214b34)nuxt/*build output contract (#35463)NuxtLinkprefetch props for custom slot (#34539)enabledoption to AsyncData (#33260)getIslandHash+hashKey+ improve hash for keys (#35583)useLayoutcomposable for accessing the resolved route layout (#35623)enabledoption inuseFetch(#35627)~,@) (#35641)updateAppConfigutil for module authors (#35651)🔥 Performance
experimental.watcher(#35143)rolldown-string(#35058)🩹 Fixes
readyevent for vite watcher (6fe539f52)causewhen we re-throw (#35387)#components(#35215)<ClientOnly>fallback tag name (#35325)inlineStylesis disabled (#35209)ssr: false(#35330)NuxtPageduring nav (#35335)useAsyncDatateardown (#35328)definePageMeta(#34526)bodyinuseFetch(#35343)page:startfinishes beforepage:finishstarts (#35408)NODE_ENVand__VUE_PROD_DEVTOOLS__(#35444)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.