pivot-vue
pivot-vue copied to clipboard
Bump @nuxt/vite-builder and nuxt in /nuxt
Bumps @nuxt/vite-builder to 3.15.3 and updates ancestor dependency nuxt. These dependencies need to be updated together.
Updates @nuxt/vite-builder from 3.14.159 to 3.15.3
Release notes
Sourced from @​nuxt/vite-builder's releases.
v3.15.3
3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99 and https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the
devServer.corsoptions in yournuxt.config, which may be relevant if you are developing with a custom hostname:export default defineNuxtConfig({ devServer: { cors: { origin: ['https://custom-origin.com'], }, }, })✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --forceThis will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
🔥 Performance
- kit,nuxt: Don't resolve paths from local layers/modules (#30650)
- nuxt: Reduce number of
mkdirSynccalls (#30651)- nuxt: Reduce unnecessary template updating (#30684)
- kit: Reduce duplication between
findPathandresolvePath(#30682)- kit: Run components compat check synchronously (#30685)
- nuxt: Early return from annotation for non-object syntax plugins (#30683)
- nuxt: Enable
Transitioncomponent only on client side (#30720)🩹 Fixes
... (truncated)
Commits
048f974v3.15.3c6056bdchore(deps): update all non-major dependencies (3.x) (#30733)406db5bfix(vite,webpack): restrict access via cors to local origins + allow configur...09d8db5chore(deps): update vitest to v3.0.4 (3.x) (#30724)10a5495fix(vite): inline shared folder in dev mode (#30690)f1c2948chore(deps): update all non-major dependencies (3.x) (#30694)64efadechore(deps): update vitest to v3.0.3 (3.x) (#30692)9bd71e4fix(vite): add backinvalidateModulecallb3f0c14chore(deps): update all non-major dependencies (3.x) (#30687)d2a95c5fix(vite): drop unneeded call to invalidate module- Additional commits viewable in compare view
Updates nuxt from 3.14.159 to 3.15.3
Release notes
Sourced from nuxt's releases.
v3.15.3
3.15.3 is the next regularly scheduled patch release.
👀 Highlights
CORS configuration for dev server
Alongside a range of improvements, we've also shipped a significant fix to impose CORS origin restrictions on the dev server. This applies to your Vite or Webpack/Rspack dev middleware only.
This is a significant/breaking change we would not normally ship in a patch but it is a security fix (see https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99 and https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47) and we urge you to update ASAP.
You can configure the allowed origins and other CORS options via the
devServer.corsoptions in yournuxt.config, which may be relevant if you are developing with a custom hostname:export default defineNuxtConfig({ devServer: { cors: { origin: ['https://custom-origin.com'], }, }, })✅ Upgrading
As usual, our recommendation for upgrading is to run:
npx nuxi@latest upgrade --forceThis will refresh your lockfile as well, and ensures that you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
🔥 Performance
- kit,nuxt: Don't resolve paths from local layers/modules (#30650)
- nuxt: Reduce number of
mkdirSynccalls (#30651)- nuxt: Reduce unnecessary template updating (#30684)
- kit: Reduce duplication between
findPathandresolvePath(#30682)- kit: Run components compat check synchronously (#30685)
- nuxt: Early return from annotation for non-object syntax plugins (#30683)
- nuxt: Enable
Transitioncomponent only on client side (#30720)🩹 Fixes
... (truncated)
Commits
048f974v3.15.3e96a96dperf(nuxt): enableTransitioncomponent only on client side (#30720)cb7f30afix(nuxt): deep clone extracted page meta (#30717)09d8db5chore(deps): update vitest to v3.0.4 (3.x) (#30724)a49329bci: reenable nuxt benchmarking (#30711)c5a84fdperf(nuxt): early return from annotation for non-object syntax plugins (#30683)f1c2948chore(deps): update all non-major dependencies (3.x) (#30694)8bcaf22chore(deps): update devdependency unimport to v4 (3.x) (#30702)2669184fix(nuxt): do not warn about[[optional dynamic params (#30619)64efadechore(deps): update vitest to v3.0.3 (3.x) (#30692)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.