chore(deps): bump @nuxt/vite-builder and nuxt by dependabot[bot] · Pull Request #313 · fuzzzerd/NoteToSelf
Bumps @nuxt/vite-builder to 3.15.4 and updates ancestor dependency nuxt. These dependencies need to be updated together.
Updates @nuxt/vite-builder from 3.13.1 to 3.15.4
Release notes
Sourced from @nuxt/vite-builder's releases.
v3.15.4
3.15.4 is the next patch release.
✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --forceThis will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
🩹 Fixes
- nuxt: Improve error logging when parsing with
acorn(#30754)- nuxt: Clear island uid before saving into the payload (#30767)
- kit: Load
@nuxt/schemafromnuxtpackage dir (#30774)- nuxt: Allow restarting nuxt on paths outside
srcDir(#30771)- nuxt: Don't warn about calling
useRoutein SFC setup (#30788)- webpack: Disallow cross-site requests in no-cors mode (#30757)
- vite: Restore
externalityfor dev server externals (#30802)💅 Refactors
- vite: Use new rollup
chunk.namesfor asset names (#30780)❤️ Contributors
- Daniel Roe (
@danielroe)- Peter Radko (
@Gwynerva)- Lansi (
@lansi951)- Julien Huang (
@huang-julien)- Norbiros (
@Norbiros)v3.15.3
3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see GHSA-4gf7-ff8x-hq99 and GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the
devServer.corsoptions in yournuxt.config, which may be relevant if you are developing with a custom hostname:export default defineNuxtConfig({ </tr></table>
... (truncated)
Commits
244da17v3.15.456d889efix(vite): restoreexternalityfor dev server externals (#30802)325ed41refactor(vite): use new rollupchunk.namesfor asset names (#30780)940bcb8chore(deps): update all non-major dependencies (3.x) (#30747)048f974v3.15.3c6056bdchore(deps): update all non-major dependencies (3.x) (#30733)406db5bfix(vite,webpack): restrict access via cors to local origins + allow configur...09d8db5chore(deps): update vitest to v3.0.4 (3.x) (#30724)10a5495fix(vite): inline shared folder in dev mode (#30690)f1c2948chore(deps): update all non-major dependencies (3.x) (#30694)- Additional commits viewable in compare view
Updates nuxt from 3.13.1 to 3.15.4
Release notes
Sourced from nuxt's releases.
v3.15.4
3.15.4 is the next patch release.
✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --forceThis will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
🩹 Fixes
- nuxt: Improve error logging when parsing with
acorn(#30754)- nuxt: Clear island uid before saving into the payload (#30767)
- kit: Load
@nuxt/schemafromnuxtpackage dir (#30774)- nuxt: Allow restarting nuxt on paths outside
srcDir(#30771)- nuxt: Don't warn about calling
useRoutein SFC setup (#30788)- webpack: Disallow cross-site requests in no-cors mode (#30757)
- vite: Restore
externalityfor dev server externals (#30802)💅 Refactors
- vite: Use new rollup
chunk.namesfor asset names (#30780)❤️ Contributors
- Daniel Roe (
@danielroe)- Peter Radko (
@Gwynerva)- Lansi (
@lansi951)- Julien Huang (
@huang-julien)- Norbiros (
@Norbiros)v3.15.3
3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see GHSA-4gf7-ff8x-hq99 and GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the
devServer.corsoptions in yournuxt.config, which may be relevant if you are developing with a custom hostname:export default defineNuxtConfig({ </tr></table>
... (truncated)
Commits
244da17v3.15.4ceaf0f5chore(deps): update all non-major dependencies (3.x) (#30804)626eba0fix(nuxt): don't warn about callinguseRoutein SFC setup (#30788)7a1e5c8fix(nuxt): allow restarting nuxt on paths outsidesrcDir(#30771)ca2d91ffix(kit): load@nuxt/schemafromnuxtpackage dir (#30774)b78da56fix(nuxt): clear island uid before saving into the payload (#30767)e0c47f9fix(nuxt): improve error logging when parsing withacorn(#30754)940bcb8chore(deps): update all non-major dependencies (3.x) (#30747)048f974v3.15.3e96a96dperf(nuxt): enableTransitioncomponent only on client side (#30720)- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.