3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99 and https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the devServer.cors options in your nuxt.config, which may be relevant if you are developing with a custom hostname:
export default defineNuxtConfig({
devServer: {
cors: {
origin: ['https://custom-origin.com'],
},
},
})
✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --force
This will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
compare changes
🔥 Performance
- kit,nuxt: Don't resolve paths from local layers/modules (#30650)
- nuxt: Reduce number of
mkdirSync calls (#30651)
- nuxt: Reduce unnecessary template updating (#30684)
- kit: Reduce duplication between
findPath and resolvePath (#30682)
- kit: Run components compat check synchronously (#30685)
- nuxt: Early return from annotation for non-object syntax plugins (#30683)
- nuxt: Enable
Transition component only on client side (#30720)
🩹 Fixes
- vite: Override previous
#app-manifest alias (#30618)
- kit,nuxt,schema,vite: Improve watching behaviour (#30620)
- nuxt: Fall back to
plugin.src for variable name generation (#30649)
- schema: Allow overriding
dev/test environment value (#30667)
- vite: Drop unneeded call to invalidate module (d2a95c542)
- vite: Add back
invalidateModule call (9bd71e498)
- nuxt: Do not warn about
[[ optional dynamic params (#30619)
- vite: Inline shared folder in dev mode (#30690)
- nuxt: Deep clone extracted page meta (#30717)
- vite,webpack: Restrict access via cors to local origins + allow configuration via
devServer.cors (406db5b4d)
💅 Refactors
- vite: Drop
externality and use vite internal config (#30634)
📖 Documentation
- Add link to custom
useFetch example (#30629)
- Fix example command (#30628)
- Fix links to
nuxi source code (4fabe0025)
- Add description for prefetch and other details of
NuxtLink (#30614)
- Update nuxt/content example (542987627)
- Adjust examples, type and description for
addRouteMiddleware (#30656)
- Explain how to use
ClientOnly with onMounted hook (#30670)
- Update links to unhead source (eb5344b43)
- Add more context about
navigation mode in callOnce composable (#30612)
- Add example on how to disable default routes for ssg (#30729)
📦 Build
- schema: Use new
inlineDependencies option (01adefcec)
🏡 Chore
🤖 CI
- Run bundle size assertion outside of matrix (#30688)
- Reenable nuxt benchmarking (#30711)
❤️ Contributors
- Alex Liu (@Mini-ghost)
- Daniel Roe (@danielroe)
- Alan Schio (@schirrel)
- xjccc (@xjccc)
- Saeid Zareie (@Saeid-Za)
- Zakhar Shymanchyk (@zshimanchik)
- Arturs Jansons (@iegik)
- Maxime Pauvert (@maximepvrt)