Skip to content

chore(deps): update nest monorepo to v12 - #775

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-nest-monorepo
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-nest-monorepo

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@nestjs/cli ^11.0.14 → ^12.0.0 age confidence
@nestjs/common (source) ^11.1.13 → ^12.0.0 age confidence
@nestjs/common (source) ^11.0.0 → ^11.0.0 || ^12.0.0 age confidence
@nestjs/core (source) ^11.1.11 → ^12.0.0 age confidence
@nestjs/core (source) ^11.0.0 → ^11.0.0 || ^12.0.0 age confidence
@nestjs/platform-express (source) ^11.0.1 → ^12.0.0 age confidence
@nestjs/platform-socket.io (source) ^11.1.14 → ^12.0.0 age confidence
@nestjs/platform-socket.io (source) ^11.0.0 → ^11.0.0 || ^12.0.0 age confidence
@nestjs/schematics ^11.0.9 → ^12.0.0 age confidence
@nestjs/testing (source) ^11.1.11 → ^12.0.0 age confidence
@nestjs/websockets (source) ^11.1.14 → ^12.0.0 age confidence
@nestjs/websockets (source) ^11.0.0 → ^11.0.0 || ^12.0.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

nestjs/nest-cli (@​nestjs/cli)

v12.0.8

Compare Source

What's Changed

  • fix(compiler): preserve CommonJS entry exports in rspack and webpack builds by @​KAPUIST in #​3599
  • fix(compiler): preserve parent links for aliased re-exports by @​KAPUIST in #​3601

Full Changelog: nestjs/nest-cli@12.0.7...12.0.8

v12.0.7

Compare Source

What's Changed

New Contributors

Full Changelog: nestjs/nest-cli@12.0.6...12.0.7

v12.0.6

Compare Source

What's Changed

New Contributors

Full Changelog: nestjs/nest-cli@12.0.5...12.0.6

v12.0.5

Compare Source

What's Changed

New Contributors

Full Changelog: nestjs/nest-cli@12.0.4...12.0.5

v12.0.4

Compare Source

v12.0.3

Compare Source

  • chore: flip the default (f194021)

v12.0.2

Compare Source

  • chore: observe prompt changes (3a2773d)

v12.0.1

Compare Source

What's Changed

New Contributors

Full Changelog: nestjs/nest-cli@12.0.0...12.0.1

v12.0.0

Compare Source

What's Changed

@nestjs/cli is now a native ES module, and the major version is aligned with the Nest 12 release line. Alongside the ESM move, the CLI no longer bundles webpack: every bundler-related package is an optional peer dependency now, so a default install is substantially smaller and you pull in only the builder you actually use. There are also two new commands — nest upgrade and nest deploy.

ESM migration

The package is published as pure ESM ("type": "module", compiled with NodeNext). All internal imports carry explicit .js extensions and the build output is ESM-only.

For the common case this is invisible — nest is a binary, and it keeps running your CJS and ESM projects alike. It matters if you import the CLI's internals programmatically (custom builders, plugin harnesses, scripts that drive @nestjs/cli/lib/...): those imports now resolve to ESM.

webpack is no longer a dependency

webpack, fork-ts-checker-webpack-plugin, tsconfig-paths-webpack-plugin, and webpack-node-externals moved from dependencies to optional peer dependencies, joining @swc/cli and @swc/core.

If you build with tsc (the default) or with SWC, nothing changes. If you use --builder webpack (or "webpack": true in nest-cli.json), install the bundler yourself:

npm i -D webpack webpack-node-externals fork-ts-checker-webpack-plugin tsconfig-paths-webpack-plugin

When a builder's peer dependency is missing, the CLI now reports the actual missing package name instead of surfacing the raw resolution error.

Rspack support

@rspack/core is supported as an optional peer dependency (^1.7.7 || ^2.1.10) and is the builder that nest new scaffolds into nest-cli.json for new projects.

  • --builder rspack on nest build and nest start
  • --rspackPath [path] to point at a custom Rspack config, mirroring --webpackPath
  • Source maps are enabled in the Rspack defaults

New: nest upgrade

A new command (aliased nest update) that runs the upgrade schematic to migrate a Nest v11 project to v12 — dependency bumps, tsconfig and nest-cli.json migrations, and codemods for @nestjs/config, GraphQL, and NATS. See the @nestjs/schematics release notes for what the migration itself does.

nest upgrade

Options: -d, --dry-run, -s, --skip-install, -t, --tag [tag] (use a dist-tag such as next instead of the default version ranges), -c, --collection [name], and --observe / --no-observe to answer the @nestjs/observe prompt up front.

New: nest deploy

Deploy an application to the cloud, powered by Mau. Every option is forwarded verbatim to mau deploy, so the command claims no flags of its own.

nest deploy

Path confinement for build output

Build output and clean-up paths are now confined to the project directory by default. Symlinks are resolved before writing, so a dist that is itself a symlink pointing outside the project no longer lets a write escape.

Monorepo layouts that legitimately emit outside the project root can opt back out:

{
  "compilerOptions": {
    "allowOutsidePaths": true
  }
}

Monorepo and asset handling

  • Parallel builds — nest build --all --parallel [concurrency] builds monorepo projects concurrently, with an optional concurrency limit.
  • Library assets — compilerOptions.includeLibraryAssets pulls assets from libraries into an application build.
  • Watch-mode restarts — asset changes restart the application in watch mode, debounced so a burst of writes triggers one restart. The build now awaits watcher close, so it no longer races shutdown.
  • Asset path stripping is aligned with the effective TypeScript rootDir.

Compiler internals

  • glob is gone. It is replaced by an internal fs-based helper built on minimatch, which is now a direct dependency. Symlink traversal depth matches the previous behaviour.
  • A recursive fs watcher replaces chokidar in the SWC watch path.
  • SWC respects tsconfig excludes — excluded files are skipped both on build and in watch mode, and newly added files no longer inherit watch mode when transpiled.
  • --emit-declarations emits .d.ts files under the SWC builder; --no-type-check overrides the config-level setting.
  • --silent suppresses informational compiler logs.

Other improvements

  • Bun is supported as a package manager and runner, detected from bun.lock / bun.lockb.
  • nest new --skip-tests scaffolds a project without testing files, and --observe / --no-observe answers the @nestjs/observe prompt.
  • nest generate --format formats generated files with Prettier; the resource schematic accepts --type <rest|graphql|microservice> and --crud [value].
  • Clearer failures: a non-zero exit on an invalid --builder, a readable error for malformed nest-cli.json, a --parallel value that is validated instead of looping forever, and an explicit message from nest info when no @nestjs/* dependencies are declared.
  • nest info and terminal-width detection prefer process.stdout.columns over shelling out to tput.
  • Plugin metadata emits .js extensions on dynamic imports under nodenext resolution.
  • .tsbuildinfo is removed when deleteOutDir is set.

Toolchain

TypeScript 6 (~6.0.2), @angular-devkit/* 22, commander 15, @inquirer/prompts 8, ora 9, node-emoji 2, and chokidar 5. Internally the CLI moved from Jest to Vitest and from ESLint to oxlint. engines.node stays at >= 20.11.


See the migration guide for the full picture.

v11.0.24

Compare Source

  • fix(compiler): fail fast when typescript lacks the programmatic api (3c6b4ac)
  • refactor: move available languages closer to first usage (1697b7f)
  • refactor: delete unused gulp tool utility helper file (75b57c4)
  • fix(runners): remove duplicated binary in failed command message (54b08ae)

v11.0.23

Compare Source

  • Revert "fix(compiler): validate delete out dir paths before rm" (0dd0e3e)
  • Revert "fix(compiler): validate asset output paths" (728f80c)

v11.0.22

Compare Source

  • fix(cli): resolve Windows path separator bug in plugin loader (9e502bd)
  • fix(compiler): validate asset output paths (c4342b2)
  • fix: Update CRUD option to accept a value for generating entry points (4c0e2ca)
  • feat: Add type and CRUD options in generate command (b19856a)

v11.0.21

Compare Source

v11.0.20

Compare Source

v11.0.19

Compare Source

What's Changed

Full Changelog: nestjs/nest-cli@11.0.18...11.0.19

v11.0.18

Compare Source

What's Changed

New Contributors

Full Changelog: nestjs/nest-cli@11.0.17...11.0.18

v11.0.17

Compare Source

What's Changed

Full Changelog: nestjs/nest-cli@11.0.16...11.0.17

v11.0.16

Compare Source

v11.0.15

Compare Source

What's Changed

New Contributors

Full Changelog: nestjs/nest-cli@11.0.14...11.0.15

nestjs/nest (@​nestjs/common)

v12.1.2

Compare Source

v12.1.1

Compare Source

v12.1.1 (2026-09-28)
Bug fixes
Enhancements
Committers: 13

v12.1.0

Compare Source

v12.1.0 (2026-09-23)
Bug fixes
Enhancements
Committers: 9

v12.0.4

Compare Source

v12.0.4 (2026-09-21)
Bug fixes
Enhancements
Dependencies
Committers: 10

v12.0.3

Compare Source

v12.0.3 (2026-09-15)
Bug fixes
Dependencies
Committers: 4

v12.0.2

Compare Source

v12.0.2 (2026-09-14)
Bug fixes
Enhancements
Dependencies
Committers: 16

v12.0.1

Compare Source

v12.0.0

Compare Source

NestJS v12.0.0

NestJS 12 is centered around ESM-ready packages, first-class Standard Schema support for validation and serialization, a rebuilt CLI, and native observability through the new @nestjs/observe SDK.

Existing CommonJS applications keep working — migrating your own code to ESM is entirely optional.

📖 Full migration guide


Upgrading

Upgrade the CLI first, since the upgrade command ships with it:

npm i -g @nestjs/cli@latest

Then, from the root of your project:

nest upgrade

nest upgrade moves every @nestjs/* package to its v12-compatible major at once and applies the mechanical parts of the migration for you — nest-cli.json webpack options, the GraphQL playground → graphiql rename and subscriptions transport swap, the NATS package replacement, @nestjs/config validation options, Jest and Joi bumps — then prints a report of everything it changed and everything you still need to review by hand. Run it with --dry-run first to see that report without touching your files.

It deliberately does not migrate your project to ESM, Vitest, or oxlint. Those are the defaults for newly generated projects; existing projects adopt them on their own schedule.

Node.js: v12 requires Node.js v20.19+ or v22.12+. Both require(esm) and the ESM packages depend on it; the upgrade command refuses to run on older releases (including the 21.x line). The latest active LTS is recommended.


Highlights
ESM packages

All core Nest packages now ship as ESM. Thanks to require(esm) in modern Node.js, most existing CommonJS applications continue to work without a rewrite. Review custom bootstrapping scripts, build tooling, and test runners if they assume CommonJS-only packages.

nest new now asks whether to scaffold a CommonJS or an ESM project.

Standard Schema validation

Route parameter decorators — @Body(), @Query(), @Param(), @RawBody() — accept a new schema option, designed for Standard Schema compatible libraries such as Zod, Valibot, and ArkType:

@Post()
create(@Body({ schema: createUserSchema }) body: CreateUserDto) {
  return this.usersService.create(body);
}

@Get(':id')
findOne(@Param('id', { schema: z.coerce.number().int().positive() }) id: number) {
  return this.usersService.findOne(id);
}

The decorator only attaches metadata; register the new StandardSchemaValidationPipe to validate against it:

app.useGlobalPipes(new StandardSchemaValidationPipe());

The same schemas feed OpenAPI generation. The decorator-based class-validator workflow remains fully supported, with no plan to remove it.

Standard Schema serialization

StandardSchemaSerializerInterceptor validates and transforms outgoing responses with the same ecosystem:

@UseInterceptors(StandardSchemaSerializerInterceptor)
@SerializeOptions({ schema: userResponseSchema })
@Get(':id')
findOne(@Param('id') id: string) {
  return this.usersService.findOne(id);
}

Pick per use case: ValidationPipe / ClassSerializerInterceptor for class-based DTOs, the Standard Schema variants when your schemas already exist.

Native observability — @nestjs/observe

The official NestJS Observe SDK plugs into Nest's own request lifecycle through the instrument application option, rather than patching the HTTP server like a generic APM agent. Requests, jobs, errors, and traces are reported in terms of your controllers, providers, resolvers, and queue consumers:

export const { ObserveModule, ObserveInstrument } = createObserveModule();

const app = await NestFactory.create(AppModule, {
  instrument: ObserveInstrument,
});

Auto-instrumentation covers HTTP, GraphQL, gRPC, and microservice transports, plus queue consumers and cron runs — no manual span wiring and no collector to run. Opt-in and new; nothing to migrate. nest new and nest upgrade can wire it up for you (--observe). See the Observability chapter.

Config module on Standard Schema

@nestjs/config moves from Joi-specific validation to Standard Schema. validationSchema now accepts any compatible schema:

ConfigModule.forRoot({
  validationSchema: z.object({
    NODE_ENV: z.enum(['development', 'production', 'test']).default('development'),
    PORT: z.coerce.number().default(3000),
  }),
});

Existing Joi schemas still work with two caveats: upgrade to Joi v18+ (the first release implementing Standard Schema), and move library-specific settings under validationOptions.libraryOptions.

Route conflict diagnostics

Routes are registered in declaration order, so on order-sensitive adapters @Get(':id') can silently shadow a @Get('me') declared after it. Two opt-in options surface this:

const app = await NestFactory.create(AppModule, {
  routeConflictPolicy: { duplicate: 'error', shadow: 'warn' },
  routeResolutionStrategy: 'specificity',
});

Both default to the previous behavior, so nothing changes unless you set them.

Machine-readable error codes

HttpExceptionOptions accepts an errorCode that is serialized into the response body, so clients branch on a stable identifier instead of parsing message strings:

throw new BadRequestException('Password is too weak', { errorCode: 'WEAK_PASSWORD' });
Structured logging params

ConsoleLogger now treats plain objects passed after the message as structured params of the same log entry instead of separate records:

logger.log('User created', { userId: 1, email: 'foo@bar.com' });

In JSON mode they nest under params, or spread into the root with flattenParams. On by default; set structuredParams: false to restore the old behavior.


CLI (@nestjs/cli v12)

The CLI was rebuilt in nestjs/nest-cli#3280: the entire source migrated to ESM, tests moved from Jest to Vitest, e2e tests were added for every command, and command classes were refactored to take typed context objects instead of untyped inputs and option arrays.

New commands

  • nest upgrade (alias update) — upgrades a v11 project to v12 and applies the migration steps described above.
  • nest deploy — deploys your application to the cloud via Mau, installing @nestjs/mau on first use and forwarding every argument straight through.

Defaults and tooling

  • Rspack is the new default bundler for monorepos. The --webpack / --webpackPath flags (and their webpack / webpackConfigPath counterparts in nest-cli.json) are deprecated in favor of --builder rspack.
  • oxlint replaces ESLint in generated projects.
  • Vitest is the default test runner for ESM projects; CommonJS projects continue with Jest.
  • bun is now a supported package manager, alongside npm, yarn, and pnpm.
  • The decorator schematic generates decorators using the preferred `Reflector.createDe

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on tuesday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/major-nest-monorepo branch from 3ffe224 to bbcb6ca Compare October 6, 2026 10:53
@renovate
renovate Bot force-pushed the renovate/major-nest-monorepo branch from bbcb6ca to 918d7de Compare October 6, 2026 21:59
@futo-kritika

futo-kritika Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Re-runKritika Review

Updates Nest packages to v12 and widens SDK peer support.

3 findings · 3 important

Confidence 3/5 · high risk: Three important findings were reported and they look valid: the lockfile pairs Nest 12 with swagger 11, schedule 6, event-emitter 3 and jwt 11, whose peers only cover Nest 11. Schematics 12 also needs Node 22/24/26 and TypeScript 6, but the repo pins Node 25 and TypeScript 5.9. This is a major framework bump that other packages depend on.

Findings

Summary

The change upgrades the framework, adapters, CLI, and testing packages while retaining Nest 11 in the SDK's framework peer ranges. The migration needs compatible companion packages and aligned Node and TypeScript tooling before the dependency graph meets the new packages' declared requirements.

Sources consulted

Commands offered: curl, fd, gh, jq, rg, yq; run: gh, rg, curl.
1 diff file(s) left out of the prompt to fit its budget: pnpm-lock.yaml.

Reviews (1) · Last reviewed commit: "chore(deps): update nest monorepo to v12" · kritika with openai/gpt-6.1-sol

Comment thread pnpm-workspace.yaml
Comment on lines +27 to +28
'@nestjs/common': ^12.0.0
'@nestjs/core': ^12.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[important · correctness] Complete the companion-package migration to Nest 12

The resulting dependency graph violates the companion packages' declared compatibility: the lockfile retains @nestjs/swagger@11.2.5 (common/core peers ^11.0.1), @nestjs/schedule@6.1.1 and @nestjs/event-emitter@3.0.1 (peers only Nest 10/11), and @nestjs/jwt@11.0.2 (common only through Nest 11), while supplying Nest 12 to them. The SDK also still requires Swagger 11 in its published peers, so its newly advertised Nest 12 support cannot satisfy Swagger's peer contract. Complete the companion migration with releases explicitly supporting Nest 12 instead of leaving this unsupported combination in the lockfile.

Suggested fix

Upgrade Swagger to ^12.0.0, update the other companion packages to releases declaring Nest 12 support, adjust the SDK's companion peer ranges accordingly, and regenerate the lockfile. If those integrations cannot yet be migrated, retain Nest 11 until they can.

Prompt for a coding agent
In pnpm-workspace.yaml at lines 27-28, complete the Nest 12 dependency migration rather than upgrading only common/core: update @nestjs/swagger to ^12.0.0 and select releases of @nestjs/jwt, @nestjs/schedule, and @nestjs/event-emitter whose declared peers include Nest 12. Check the other Nest integrations for the same constraint and regenerate pnpm-lock.yaml. In packages/yucca-sdk/orchestration-api/package.json, update the swagger and schedule peer ranges to match the supported companion versions while retaining the intended Nest 11 compatibility where valid.

Comment thread pnpm-workspace.yaml
'@nestjs/swagger': ^11.2.5
'@nestjs/testing': ^11.1.11
'@nestjs/websockets': ^11.1.14
'@nestjs/testing': ^12.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[important · reliability] Align the Node pins with the schematics engine requirement

@nestjs/schematics@12.0.6 explicitly requires Node ^22.22.3 || ^24.15.0 || >=26.0.0; Node 25 is excluded. This repository pins Node 25.9.0 in mise and uses node:25 images for the application builds, so the upgraded generators are outside their supported runtime everywhere those pins are used. The upstream migration guide specifically distinguishes this higher schematics requirement from the framework's lower runtime requirement.

Suggested fix

Coordinate this bump with a move of the mise Node pin and Node Docker images to a supported line, or defer the schematics bump.

Prompt for a coding agent
For the @nestjs/schematics upgrade at pnpm-workspace.yaml line 36, reconcile its Node requirement with .mise/config.toml's node 25.9.0 pin and the node:25 Docker images under packages. Move the development and image runtimes to a supported Node line satisfying ^22.22.3 || ^24.15.0 || >=26.0.0, or defer the schematics upgrade until the runtime migration is ready.

Comment thread pnpm-workspace.yaml
'@nestjs/swagger': ^11.2.5
'@nestjs/testing': ^11.1.11
'@nestjs/websockets': ^11.1.14
'@nestjs/testing': ^12.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[important · correctness] Upgrade the compiler alongside the v12 schematics

The locked schematics release declares a required typescript: >=6.0.0 peer, but the shared catalog still specifies typescript: ^5.9.3, including in the orchestration API that directly depends on schematics. This leaves the tooling upgrade with an unsatisfied required compiler contract. Nest's v12 upgrade schematic explicitly upgrades TypeScript to v6 for this reason; the dependency bump needs that accompanying migration too.

Suggested fix

Upgrade the TypeScript catalog to a v6-compatible range, apply the necessary tsconfig migrations, and regenerate the lockfile.

Prompt for a coding agent
In pnpm-workspace.yaml, reconcile the @nestjs/schematics v12 change at line 36 with the typescript catalog entry at line 129. Upgrade the shared TypeScript catalog to a v6-compatible range, regenerate pnpm-lock.yaml, and apply any required tsconfig migrations across its consumers rather than continuing to supply TypeScript 5.9 to schematics.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants