⚡️ Announcement for Vize
Vize is entering the Real World Testing phase.
https://t.co/bPOFfg9kIl
Looking for:
・Bug reports (Issues)
・Pull Requests
・Medium-to-large Vue projects to test against
The next milestone is v1.0.0-alpha.
All our main websites are now on void / cloudflare
https://t.co/PisLyE58F4
https://t.co/cbLf0kyfRa
https://t.co/G6dtN2ghCk
https://t.co/2rYacZ14pF
https://t.co/8G6ajsNBuN
Some notes on the acquisition.
- Vue is not part of this - it remains an independent project. That said, the acquisition does make it possible for me to better financially support the people contributing to or working full-time on Vue. More on this soon.
- Nothing really changes for the relationship between Vue itself and the people in the Vue ecosystem now working at Vercel. I remain close friends with the Nuxt team and Eduardo. I’m confident that @rauchg will continue to support Nuxt the same way we intended to keep Vite vendor-neutral.
VoidZero is joining Cloudflare.
Our mission stays the same: to make JavaScript developers more productive than ever before. Vite, Vitest, Rolldown, Oxc, and Vite+ remain MIT-licensed. Evan and the VoidZero team will continue leading them.
Cloudflare shares our commitment to open source. Together, we can keep investing in the tooling developers rely on every day, while bringing the Vite ecosystem and Cloudflare’s platform even closer together.
📦 @pnpmjs 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal.
As npm adds more release paths, registry metadata needs to make it clear how each package version was published.
https://t.co/hNerib86mu
👀 React Compiler in Rust - Exciting update from @rickyfm
TLDR:
- Rust compiler ➡️ 99.9% the same output as the original
- Confident ➡️ merge the PR within the next weeks
- Can be tested locally
The Oxc team is already working on an integration (draft PR)
We just published 7 CVEs identifying security vulnerabilities in React Router and Remix v2
We recommend updating to the latest appropriate versions:
- React Router v7 -- 7.16.0
- React Router v6 -- 6.30.4
- Remix v2 -- 2.17.5
Details, links, and package ranges are listed below
We've published a Browser Mode security advisory.
CDP-capable providers like Playwright Chromium with the browser API exposed to the network allowed attackers to run code on the host.
Update vitest/browser to 5.0.0-beta.4, 4.1.8, or 3.2.6.
Vite+ users: Upgrade to 0.1.24
We've published two Windows advisories:
◇ If Vite runs with `--host`, denied files may have been reachable over the network
◇ launch-editor with NTLM enabled may leak NTLMv2 hashes via a malicious page
Update to Vite 8.0.16/7.3.5/6.4.3, Vite+ 0.1.24, and launch-editor 2.14.1