Skip to content

chore(deps): update all non-major dependencies - #262

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@iconify-json/lucide ^1.2.136 → ^1.2.140 age confidence
@iconify-json/simple-icons ^1.2.97 → ^1.2.99 age confidence
@nuxt/test-utils ^4.3.2 → ^4.3.3 age confidence
@nuxt/ui (source) ^4.11.2 → ^4.11.3 age confidence
@types/node (source) ^24.13.6 → ^24.19.1 age confidence
docus ^5.13.0 → ^5.14.0 age confidence
h3-next (source) 2.0.1-rc.32 → 2.0.1 age confidence
knip (source) ^6.37.0 → ^6.40.0 age confidence
nanoid ^6.0.1 → ^6.0.2 age confidence
nuxt (source) ^4.5.2 → ^4.6.0 age confidence
oxfmt (source) ^0.70.0 → ^0.72.0 age confidence
oxlint (source) ^1.85.0 → ^1.87.0 age confidence
pg (source) ^8.23.0 → ^8.23.1 age confidence
pnpm (source) 12.8.1 → 12.10.1 age confidence
vue-i18n (source) ^11.4.12 → ^11.4.13 age confidence
vue-tsc (source) ^3.3.11 → ^3.3.12 age confidence

Release Notes

nuxt/test-utils (@​nuxt/test-utils)

v4.3.3

Compare Source

v4.3.3 is the next patch release.

👉 Changelog

compare changes

🔥 Performance
  • use h3's toWebHandler instead of node-mock-http (abe8ad944)
  • resolve h3 from the project (b5d802f03)
  • replace estree-walker with oxc-walker (8e8ca5e8b)
  • replace local-pkg with exsolve (38938a879)
  • replace c12 with native dotenv parsing (26c72afa0)
  • inline destr and scule usage (e4bfd2ebe)
  • drop node-fetch-native polyfill (6b654de5c)
  • replace nypm with package-manager-detector (#​1828)
🩹 Fixes
  • runtime-utils: type registerEndpoint against the project h3 (#​1831)
  • e2e: restore console after use nuxt kit (#​1817)
  • config: exclude aliased mock packages from optimizeDeps in browser mode (#​1816)
  • runtime: setup nuxt once per worker in no-isolate (#​1821)
  • browser: correct render helper options type (#​1822)
🏡 Chore
  • move vue to peer dependencies (e70592ffa)
  • declare supported nuxt versions as peer dependency (b473892c9)
🤖 CI
❤️ Contributors
nuxt/ui (@​nuxt/ui)

v4.11.3

Compare Source

Bug Fixes
  • App: apply the dir prop to the provided locale (#​6767) (93c40df)
  • ChatPrompt: add method="post" to prevent input leaking via GET before hydration (#​7078) (57f7699)
  • CheckboxGroup/RadioGroup: lift a hovered table item above its neighbors (#​7073) (926097a)
  • ContentSearch/DashboardSearch: use translated search label as dialog title (#​7062) (3c55cf2)
  • DashboardSidebar/Header: use translated toggle label as menu dialog title (#​7082) (51e98da)
  • EditorToolbar: use tooltip text as aria-label on icon-only buttons (#​7009) (7f0250e)
  • Form: include nested forms in parent dirty state (#​6545) (8977394)
  • Form: keep dirty state and validation in sync with input (#​7033) (56b1156)
  • Form: merge unnamed nested forms into a parent without schema (#​7034) (384fdc1)
  • module: detect kebab-case components in Pug templates (#​7045) (42ba532)
  • module: generate classes prefixed by usePrefix (#​7074) (77c92de)
  • module: use @custom-variant for light and dark variants (#​7023) (584016b)
  • ProseA: only round corners on focus (3da141c)
  • Select/SelectMenu: keep focus moved on selection (#​7083) (6138bf0)
  • Table: keep footer separator above pinned columns (#​7047) (e8756fd)
  • theme: drop double quotes from class strings (#​7039) (5a04c6c)
  • useFilter: keep labels and separators in place while sorting (#​6995) (032a152)
  • useOverlay: resolve every pending promise when reopened (#​7057) (2f50c2e)
  • utils: prevent prototype pollution in set and setAtPath (#​7077) (4bfd115)
nuxt-content/docus (docus)

v5.14.0

Compare Source

Features
Bug Fixes
h3js/h3 (h3-next)

v2.0.1

Compare Source

compare changes

🚀 Enhancements
  • rules: Skip redirect when the request is already at the target (#​1559)
🩹 Fixes
  • cookie: Include partitioned in the distinct-cookie key (#​1553)
  • sse: Preserve buffered events during overlapping flushes (#​1555)
  • static: Set vary header when a single encoding is accepted (#​1556)
  • static: Honor q-values and case in accept-encoding (#​1560)
  • mime: Add .mjs and .cjs to COMMON_MIME_TYPES (#​1566)
  • rules: Normalize rule keys like routes and tighten the shape guard (7cbf21c)
  • rules: Let a narrower pattern reinstate a rule reset on another reading (3f1c9e5)
  • rules: Allow headers: false in RouteRuleConfig (edcc329)
  • validate: Preserve repeated query values in defineValidatedHandler (#​1562)
  • cookie: Size cookie chunks by their encoded length (#​1565)
  • static: Resolve the MIME type of a precompressed variant from the requested asset (#​1564)
  • mount: Reject // after base (1161eb7)
  • session: Keep loaded session data prototype-free (46bc1a2)
💅 Refactors
📖 Documentation
  • Document raw query access via event.url.search (#​1551)
🌊 Types
  • auth: BasicAuth context fields are always set (#​1550)
🏡 Chore
❤️ Contributors

v2.0.1-rc.33

Compare Source

compare changes

🚀 Enhancements
  • rules: Skip redirect when the request is already at the target (#​1559)
🩹 Fixes
  • cookie: Include partitioned in the distinct-cookie key (#​1553)
  • sse: Preserve buffered events during overlapping flushes (#​1555)
  • static: Set vary header when a single encoding is accepted (#​1556)
  • static: Honor q-values and case in accept-encoding (#​1560)
  • mime: Add .mjs and .cjs to COMMON_MIME_TYPES (#​1566)
  • rules: Normalize rule keys like routes and tighten the shape guard (7cbf21c)
  • rules: Let a narrower pattern reinstate a rule reset on another reading (3f1c9e5)
  • rules: Allow headers: false in RouteRuleConfig (edcc329)
  • validate: Preserve repeated query values in defineValidatedHandler (#​1562)
  • cookie: Size cookie chunks by their encoded length (#​1565)
  • static: Resolve the MIME type of a precompressed variant from the requested asset (#​1564)
  • mount: Reject // after base (1161eb7)
  • session: Keep loaded session data prototype-free (46bc1a2)
💅 Refactors
📖 Documentation
  • Document raw query access via event.url.search (#​1551)
🌊 Types
  • auth: BasicAuth context fields are always set (#​1550)
🏡 Chore
❤️ Contributors
webpro-nl/knip (knip)

v6.40.0: Release 6.40.0

Compare Source

v6.39.0: Release 6.39.0

Compare Source

v6.38.0: Release 6.38.0

Compare Source

ai/nanoid (nanoid)

v6.0.2

Compare Source

nuxt/nuxt (nuxt)

v4.6.0

Compare Source

v4.6.0 is the next minor release.

📣 Some news

🖥️ Nuxt CLI v4

Alongside the release of Nuxt v4.6, today also brings a new major release of the Nuxt CLI: @nuxt/cli v4. It ships as a dependency of nuxt, so you'll get it automatically when you upgrade.

Most of what's new is in nuxt dev:

  • an interactive terminal UI, showing URLs, startup progress and keyboard shortcuts, with panels to dive into error logs, routes, network requests and more
  • the dev server gives you more info, such as why it reloaded or restarted, which nuxt.config keys changed, where the time went during a slow start or build, and how long each module took to set up
  • a CLI-level error channel rendered with my-bad (see below), powering things like automatically reloading when a syntax error in nuxt.config.ts is fixed
  • a lock file in .nuxt/, which lets a second nuxt dev (say, one started by an agent) take over or defer to the one you started, and powers new nuxt curl and nuxt task commands that talk to the running server

There's also a new nuxt docs "<query>" search, and nuxt preview --takeover can replace a running preview server. And in general nuxt/cli is a lot smaller and starts a lot faster:

v3.37 v4.0
@nuxt/cli install size 13.1 MB 3.5 MB -73%
@nuxt/cli dependencies 70 31 -56%
nuxt dev: first paint 330 ms 50 ms 6.6x faster
nuxt dev: port bound 338 ms 104 ms 3.2x faster
nuxt dev: memory at rest (Linux) 630 MB 440 MB -30%
nuxt-dev

Although this is a major version, none of the changes should be breaking for Nuxt v4 users: we require Node.js v22.21+, v24.11+ or v26+, we drop nuxt init and only support npm create nuxt@latest, and Nuxt 2 and @nuxt/bridge are no longer supported.

👉 Check out the full Nuxt CLI v4 release notes for everything that's changed.

💡 A server-agnostic Nuxt

The biggest thing about this release is our move towards making Nuxt server-agnostic.

I feel that freedom of choice is very much a fundamental value of the web, and one that unites the whole Nuxt team.

You can use pages/ (with vue-router) or not. You can use Vite, webpack or Rspack to bundle your code. You can pick from dozens of providers to deploy to, pick any image or font provider, choose any database adapter. In every case, the framework is the same.

The server side was different. #app composables imported h3 types, server code imported from h3 and nitropack, and every module that touched the server was tied to whichever major version of those packages Nuxt happened to depend on.

This has become particularly clear as we have been upgrading to new majors of h3 and nitro, which ship breaking changes with a cascading effect throughout the whole ecosystem.

👉 This release changes that.

Alongside explicitly defining our public API in nuxt/kit (which now does not refer to external packages), Nuxt now specifies our own types for the request event, route rules and typed $fetch, and we expose an import surface (nuxt/server) for the server utilities that will be needed by most apps.

This is the culmination of work we started almost a year ago, making it possible to use any server builder with Nuxt, not just Nitro (#​33462).

Of course, under the hood, nuxt/server is still powered by Nitro by default - though we are also announcing a second, experimental implementation, @nuxt/vite-server, which allows pure-Vite server builds using the Vite Environment API.

[!IMPORTANT]
We believe that Nitro is still the right choice for almost everyone.

🌟 We see a number of key benefits for nuxt/server.

  1. it smooths the upgrade to Nuxt 5, which moves to Nitro v3 and h3 v2. Server code written against nuxt/server on 4.6 runs unchanged there, so a module can ship one file for both.
  2. it decouples Nuxt from the Nitro release cycle. Because we 'own' the API, we can adapt to breaking changes in Nitro or h3 without requiring a future major - and we can release Nuxt majors without having to wait for upstream releases.
  3. it makes Nuxt's code more maintainable. It helps us preserve the separation of concerns between our API - /app and /server - and the bundler + server that you ultimately want to build your app.

... and there are a number of other benefits too, from a single type surface to being able to iterate more quickly on features.

Finally, I want to say a special thank-you to @​pi0, whose relentless focus on server agnosticism and work on h3, Nitro and web-standard server primitives over the last few years is what makes a portable RequestEvent possible at all. Thank you, Pooya. ❤️

Almost every feature in this release is already in the Nuxt 5 branch, and most of the remaining Nuxt 5 defaults can be tested today with future.compatibilityVersion: 5 (more details below!).

[!TIP]
Nuxt 3 reached end-of-life on July 31, 2026, so there is no 3.x release alongside this one. If you're still on v3, the upgrade guide is waiting for you.

👀 Highlights

🤷 If you've read this far I'm afraid I have bad news for you: there's a lot more still to say! Nuxt 4.6 is one of our biggest minor releases, with over 420 commits since v4.5.2.

... so, you might want to grab a coffee! ☕️

🧩 nuxt/server

It has been asked for for a long time, and it now exists (#​36275)!

nuxt/server is a new import source for server code: handlers, middleware and utilities - a complement to nuxt/app. Where nuxt/app is for the part of your application that also runs in the browser, nuxt/server is for the part that only runs on the server.

import { defineEventHandler, getQuery } from 'nuxt/server'

export default defineEventHandler((event) => {
  const { name } = getQuery<{ name?: string }>(event)
  return { message: `Hello, ${name ?? 'world'}!` }
})

The utilities use web standards and are typed against a portable RequestEvent:

event.req         // Request
event.url         // URL
event.res         // { status, statusText, headers }
event.res.headers // Headers
event.context     // per-request context

Under @nuxt/nitro-server they are backed by Nitro and h3, but you never import from either.

So the same handler runs under Nitro v2, Nitro v3 or @nuxt/vite-server, and a module that imports from nuxt/server doesn't need a peer dependency on h3 or nitropack.

We think this will make a big difference in smoothing out the upgrade to Nuxt v5 and Nitro v3.

There is a typing benefit too. We no longer hoist h3 or Nitro types into your app to type useRequestEvent, $fetch or route rules, which removes a source of type conflicts when versions differ (#​36212, #​36214, #​36293).

The surface is small, and covers what published modules and user code typically need: defineEventHandler, createError/isNuxtError, request URL, headers, query, body (plain and validated with any Standard Schema library or a function), cookies, redirects, response status, getRouterParam(s), getRequestIP, handleCors, getRouteRules, useRuntimeConfig, useAppConfig and sessions.

import { defineEventHandler, readValidatedBody } from 'nuxt/server'
import { z } from 'zod'

export default defineEventHandler(async (event) => {
  const user = await readValidatedBody(event, z.object({ name: z.string() }))
  return { created: user.name }
})

We encourage you to use web APIs (event.req.headers, for example), or raise an issue if there's functionality you're missing from nuxt/server 🙏

If you do need to step outside nuxt/server for a particular handler, don't worry! Nothing has been taken away: import defineEventHandler and the helpers you need from h3 or nitropack/runtime as before, and that handler works exactly as it did on Nuxt 4.5.

import { defineEventHandler, readMultipartFormData } from 'h3'

export default defineEventHandler(async (event) => {
  const parts = await readMultipartFormData(event)
  return { received: parts?.length ?? 0 }
})

[!IMPORTANT]
On Nuxt 4, the auto-imported defineEventHandler, getQuery, readBody and the rest are still h3's own helpers, which take a different shape of event. Import from nuxt/server explicitly, including defineEventHandler to use the new server runtime. If you mix the two, you'll see a NUXT_E8012 error which should tell you which import to change.

A few helpers also behave differently from their h3 v1 namesakes: sendRedirect returns the response rather than sending it, createError takes status and statusText, and response headers are set through event.res.headers. The upgrade guide has a table of the differences.

Nothing in this release requires a migration. But if you have server code you'd like to make portable ahead of Nuxt 5, this is the best way.

👉 Read the server imports guide.

🔐 appSecret and sessions

Nuxt now has a root application secret: runtimeConfig.appSecret, set with NUXT_APP_SECRET (#​35874, thanks to @​onmax). Modules and server features derive purpose-specific secrets from it with deriveSecret(purpose), so NUXT_APP_SECRET is the only secret you need to configure.

openssl rand -base64 32

In development Nuxt generates and persists one if none is configured (and warns the first time a derived secret is used). Builds never generate one.

The first thing to use it is a set of session helpers in nuxt/server (#​36358). Sessions are sealed into a cookie with iron, so there's no server-side storage to configure:

import { defineEventHandler, useSession } from 'nuxt/server'

export default defineEventHandler(async (event) => {
  const session = await useSession<{ visits: number }>(event)
  await session.update(data => ({ visits: (data.visits ?? 0) + 1 }))
  return { visits: session.data.visits }
})

[!NOTE]
As a reminder, runtime config keys prefixed with app (runtimeConfig.app, runtimeConfig.appSecret) are reserved for Nuxt.

🎯 Typed $fetch, rebuilt

$fetch and useFetch have been typed from your server routes for a long time. But the types were derived from Nitro's InternalApi interface, and past a few hundred routes they hit TypeScript's instantiation limit with the familiar TS2589: Type instantiation is excessively deep and possibly infinite.

We've rebuilt typed fetch on top of fetchdts (#​36238). Nuxt compiles your server routes into a route tree with an exact-match table for static paths and accessors specialised to your route set. Resolution cost now scales with call sites, not with route count:

routes before after
100 1,397,361 instantiations / 0.77s 51,558 / 0.26s
300 5,774,425 / 3.49s (TS2589) 51,558 / 0.16s
1000 12,831,467 / 7.44s (TS2589) 51,558 / 0.20s
3000 (200 call sites) 71,875,148 / 53.63s (TS2589) 101,678 / 0.62s

Peak memory for the same runs dropped from 946 MB to 140 MB. 🔥

Plus, the route set also carries the body, query and headers a handler validates, so calls are checked more tightly than before:

// server/api/users.post.ts validates { title: string, count: number }
await $fetch('/api/users', { method: 'post', body: { title: 'a', count: 1 } })
await $fetch('/api/users', { method: 'post', body: { title: 'a', count: 'no' } })
//                                                                ^ not assignable to number
await $fetch('/api/users', { method: 'post' })
//           ^ body is required

On Nuxt 4 this is opt-in, because there are small changes to type inference, and hand-written ServerRoutes augmentations need a small rewrite. It is the default in Nuxt 5.

export default defineNuxtConfig({
  experimental: {
    routeTypedFetch: true,
  },
})

There's also a new experimental.strictRouteTypes option to reject calls to paths that don't exist (otherwise these just return unknown), and an 'isomorphic' mode that types your pages as GET routes too if you want to be able to $fetch from the Vue renderer with type safety.

👉 Read more in the experimental features docs.

🐛 Better errors in development with my-bad

Server-side errors in development used to look like this:

ReferenceError: foo is not defined
    at Object.<anonymous> (/_nuxt/app/pages/index.vue:1:1)

There was no source position or code frame, and the Youch iframe we rendered could not show you the frame in your own source either. Both are now fixed (#​36258, nuxt/cli#1518).

Dev SSR stack traces are now mapped before anything reads the error, and the Youch overlay has been replaced with my-bad. It renders into your app's own error page as an overlay (or as a standalone page when the app can't render one), with the mapped stack trace and a code frame from your source, and the same report is printed in your terminal. We are still working with @​atinux, @​HugoRCD and @​antfu to make these pages nicer still.

my-bad-ssr-expanded-dark my-bad-ssr-copymenu-dark

With Nuxt CLI v4, there is a single live error channel at the CLI level. It survives worker restarts, so (for example) a syntax error in nuxt.config.ts will live-reload the page once you fix it. Each error is rendered once rather than at every layer it passes through, and the same channel streams build progress and app logs to the dev panel.

🎨 A new loading screen, 404 and error pages

@​HugoRCD has redrawn the loading screen you see while the dev server starts. It is now a WebGL2 particle field that traces a mountain range behind the Nuxt lockup (#​36178), using a single shader and a single draw call. Without WebGL2 it falls back to the static lockup, and with prefers-reduced-motion the animation stops. Try hovering over it. 🏔️

Hugo also gave the built-in 404 and error pages a neutral palette and lighter type (#​36255), and @​MirkoJa added a back button to the 404 page (#​35688).

404-page-dark
⚡️ Vue Vapor support

Nuxt now supports Vue 3.6's Vapor Mode in interop mode (#​35759). Your app root stays on the virtual DOM, and you can opt individual components or pages into Vapor by adding the vapor attribute to <script setup>:

export default defineNuxtConfig({
  vue: {
    vapor: true,
  },
})
<script setup vapor lang="ts">
const count = ref(0)
</script>

<template>
  <button @click="count++">
    count is {{ count }}
  </button>
</template>

Routing,

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 218d972a-5fd1-4c38-92ea-36fe7d4c48e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 1a7f216 to 46ec7ba Compare September 26, 2026 14:06
@renovate renovate Bot changed the title chore(deps): update dependency knip to ^6.38.0 chore(deps): update all non-major dependencies Sep 26, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from 9ff89a6 to c9bdbec Compare October 4, 2026 00:30
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 7 times, most recently from 7e89461 to a3bdcf5 Compare October 7, 2026 17:53
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from a3bdcf5 to bf7ae36 Compare October 7, 2026 22:14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants