131 wires and counting

$ follow Vue.js

Keep up with Vue.js in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-05-29
stories 7

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

LANGUAGE TOOLS PATCHES SHELL INJECTION HOLE IN CI WORKFLOW

By RepoJournal · Filed · About Vue.js · Composed from the cited sources · methodology

A supply chain vulnerability in the auto-version GitHub Action could let malicious PR titles execute arbitrary commands during version bumps.

The vulnerability [1] lived in the `auto-version.yml` workflow, which pulled the PR title directly into a shell variable without sanitization. A PR title like `v3.0.0"; id; "` would execute as shell code despite existing regex checks, because GitHub Actions expands template variables before bash runs. The fix [2] now reads the PR title from environment variables instead, which bash treats as data not commands. This is the kind of supply chain risk that compounds quietly across thousands of repos using shared Actions. Update your local copy immediately if you fork language-tools.

Meanwhile, the VSCode extension got a fix [3] that restores TypeScript auto-imports in Vue files [4], closing a gap where IDE behavior diverged from standard TS. Vapor's compiler picked up two hydration fixes [5] [6] synced from core, addressing cursor tracking for nested insertions and useId evaluation order. Vue core shipped beta.13 [7] on the minor branch, so watch the changelog for what's coming next.

Action items

References

  1. [1] fix(ci): read PR title from env in `auto-version` workflow to prevent injection (#6074) ↗ vuejs/language-tools
  2. [2] fix(ci): read PR title from env in `auto-version` workflow to prevent injection ↗ vuejs/language-tools
  3. [3] fix(vscode): preserve TS auto imports behavior in Vue files (#6072) ↗ vuejs/language-tools
  4. [4] fix(vscode): preserve TS auto imports behavior in Vue files ↗ vuejs/language-tools
  5. [5] fix(compiler/vapor): preserve hydration cursor for nested insertions ↗ vuejs/vue-jsx-vapor
  6. [6] fix(compiler/vapor): preserve useId evaluation order before dynamic ↗ vuejs/vue-jsx-vapor
  7. [7] v3.6.0-beta.13 ↗ vuejs/core

Quick answers

What shipped in Vue.js on May 29, 2026?
A supply chain vulnerability in the auto-version GitHub Action could let malicious PR titles execute arbitrary commands during version bumps. In total, 4 commits, 2 pull requests, and 1 releases landed.
Who contributed to Vue.js on May 29, 2026?
2 developers shipped this update, including arpitjain099 and KazariEX.
What were the notable Vue.js updates?
fix(ci): read PR title from env in `auto-version` workflow to prevent injection (#6074), fix(ci): read PR title from env in `auto-version` workflow to prevent injection, and fix(vscode): preserve TS auto imports behavior in Vue files (#6072).