Skip to content
Oday Bakkour
Back to Knowledge Hub

Nuxt 4.6, SvelteKit 3 and Firebase 13 Release Audit

Oday Bakkour profile photo
Oday Bakkour
5 min read
Share

Nuxt 4.6 landed on October 5, SvelteKit 3.0 is now the stable line, Firebase JS SDK 13 shipped breaking AI Logic changes on October 7, and Astro 7.3.6 and 7.3.7 tightened request security. This audit covers what could be verified against primary sources (GitHub release pages, changelogs and the npm registry) in today's run.

Executive Summary

  • Nuxt 4.6.0 (Oct 5): new Nuxt CLI v4, nuxt/server imports, cookie-sealed sessions, Vue Vapor interop and a Nuxt 5 preview flag. Requires Node ^22.22.3 || ^24.15.0 || >=26.0.0. See the release notes.
  • SvelteKit 3.0.1 (Oct 6): a patch on top of the 3.0 major, which needs Vite 8, TypeScript 6 and Node 22+. Details in the changelog.
  • Firebase JS SDK 13.0.0 (Oct 7): removes VertexAIBackend, restructures the Part type and adds Firestore BSON types. See the releases page.
  • Astro 7.3.6 and 7.3.7: CSRF hardening, Host header validation for the Node adapter and a fix for security.checkOrigin. See the changelog.
  • Also on npm: Next.js 16.4.0 (Oct 6), Svelte 5.57.2, Clerk Next.js SDK 7.9.12 and supabase-js 2.117.3 (both Oct 7), and Motion 14.0.0 (Oct 2).

Nuxt 4.6

The headline is the rebuilt tooling. Nuxt CLI v4 adds an interactive nuxt dev terminal UI, a lock file in .nuxt/, and new nuxt curl, nuxt task and nuxt docs commands. nuxt init is gone, so use npm create nuxt@latest for new projects.

  • nuxt/server imports: server code can use web-standard request primitives that should run across Nitro v2, Nitro v3 and the experimental @nuxt/vite-server. Helpers differ from h3 v1: createError takes status and statusText, and headers are set through event.res.headers. Do not mix auto-imported h3 helpers with nuxt/server helpers on Nuxt 4, because that raises NUXT_E8012.
  • Sessions: a root NUXT_APP_SECRET setting enables cookie-sealed session helpers such as useSession.
  • Typed $fetch: rebuilt on fetchdts to avoid TypeScript instantiation limits on large route sets. Opt in with experimental.routeTypedFetch.
  • Vue Vapor: interop mode is enabled per component with the vapor attribute.
  • Security hardening: the internal error route is only served to error renders, dev error reports are scoped for remote peers, and unhandled error data is no longer passed to the error page.

Opt in to the Nuxt 5 defaults and the experimental Vite server builder like this:

typescript.txt
// nuxt.config.ts
export default defineNuxtConfig({
  future: { compatibilityVersion: 5 },
  experimental: { routeTypedFetch: true },
  server: { builder: 'vite' }, // experimental, Nitro stays the default
})

Upgrade with npx nuxt upgrade --dedupe. Nuxt 2 and @nuxt/bridge are no longer supported, and Nuxt 3 has reached end of life. Full notes: Nuxt v4.6.0.

SvelteKit 3.0

Version 3.0.1 only fixes generated types so relative imports work with nodenext module resolution, but it is the first patch on a major release, so the 3.0 migration is what matters. Highlights from the changelog:

  • Requirements: Node 22+, TypeScript 6, Svelte 5.56.4+, Vite 8 and @sveltejs/vite-plugin-svelte v7.
  • Removed: $app/stores, $service-worker, handleValidationError (validation errors now reach handleError with kind: 'validation') and the CSRF checkOrigin option.
  • Alias change: $lib becomes #lib, so module imports need explicit extensions.
  • Security defaults: external redirects are forbidden by default, cross-origin form submissions without a Content-Type header are rejected, and query parameters starting with x-sveltekit- are rejected.
  • Behavior: cookie path defaults to /, cookie names must be ASCII, and version polling defaults to one hour.

Firebase JS SDK 13

Firebase 13.0.0 is a breaking release for anyone using AI Logic. Per the release notes:

  • VertexAIBackend and BackendType.VERTEX_AI are removed. Use AgentPlatformBackend, whose default location is now global.
  • TemplateGenerativeModel.generateContent takes a single TemplateRequest, and templateVariables is now required.
  • Part is a discriminated union with explicit type properties, and a new UnknownPart covers raw input.
  • Firestore gains BSON type support, and Auth keeps the persisted user when the initial reload fails with a quota or rate-limit error.

To keep the previous region, pin it explicitly:

typescript.txt
import { getAI, AgentPlatformBackend } from 'firebase/ai'

const ai = getAI(app, { backend: new AgentPlatformBackend('us-central1') })

Astro 7.3.6 and 7.3.7

The Astro changelog does not label entries as security fixes, but several are security relevant:

  • 7.3.7: security.checkOrigin no longer rejects cross-origin requests with non-form content types such as application/json. It now applies only to unsafe requests with no content type or a form-style one.
  • 7.3.6: CSRF protection now accounts for modern browser headers, the Node adapter validates the Host header against security.allowedDomains, and composable astro/fetch and astro/hono handlers reject over-encoded request paths with 400.

If you deploy the Node adapter, set the allowed domains explicitly:

typescript.txt
// astro.config.mjs
export default defineConfig({
  security: { allowedDomains: [{ hostname: 'example.com' }] },
})

Other Releases Seen on npm

These versions were published recently but release notes were not reviewed in this run, so check the linked pages before upgrading: Next.js 16.4.0, Svelte 5.57.2, Clerk Next.js SDK 7.9.12, supabase-js 2.117.3 and Motion 14.0.0. Prisma is publishing 8.0.0 release candidates, and the project's releases page notes breaking changes across the series, so avoid auto-upgrading to the latest tag in CI.

Coverage Gaps

GitHub API access was unavailable in this run, so Docker, Kubernetes, PostgreSQL, Redis, Keycloak, Django, Laravel and the other stacks on the watch list were not verified today. No claims are made about them.

Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED