NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4970 most downloaded on npm
Nest - modern, fast, powerful node.js web framework (@passport)
Last release 1 months ago
27 Aug 2026
Release timing varies
gaps range from 3 weeks to 1.6 years
Some releases are documented
notes for 27 of 50 stable releases
1 version withdrawn
withdrawn after publishing
8 years old
51 releases · first in 2018
@nestjs/passport is now a native ES module , and the major version is aligned with the Nest 12 release line.
@nestjs/passport is now a native ES module, and the major version is aligned with the Nest 12 release line.
The package is published as pure ESM ("type": "module", compiled with NodeNext) behind a proper exports map. The legacy root index.js / index.d.ts / index.ts shims are gone, and deep imports into build internals (e.g. @nestjs/passport/dist/auth.guard) are no longer resolvable — import from the package root:
import { AuthGuard, PassportModule, PassportStrategy } from '@nestjs/passport';require(esm) — CommonJS still worksYou do not need to convert your app to ESM. Thanks to Node's require(esm) support, a CommonJS app can keep doing:
const { AuthGuard, PassportModule } = require('@nestjs/passport');This requires Node.js 20.19+ or 22.12+ (where require(esm) is enabled by default). On older Node versions you must either upgrade Node or move your app to ESM.
AuthGuard no longer forwards module options to passport.authenticate()defaultStrategy and property — options that belong to PassportModule.register(), not to Passport itself — were being passed straight through to passport.authenticate(), where they could collide with strategy-level options. They are now stripped before the call, so a strategy only ever receives real AuthenticateOptions.
The signature of getAuthenticateOptions() changed accordingly:
// before
getAuthenticateOptions(
context: ExecutionContext,
): Promise<IAuthModuleOptions> | IAuthModuleOptions | undefined;
// after
getAuthenticateOptions(
context: ExecutionContext,
):
| Promise<AuthGuardAuthenticateOptions>
| AuthGuardAuthenticateOptions
| undefined;AuthGuardAuthenticateOptions is exported from the package root and is passport.AuthenticateOptions with defaultStrategy explicitly disallowed. If you override getAuthenticateOptions() and return defaultStrategy, TypeScript will now flag it — remove it and set it via PassportModule.register({ defaultStrategy: '...' }) instead.
Nest 10 is no longer supported. Nest 11 remains supported, so you can adopt this release before or after upgrading to Nest 12.
npm i @nestjs/passport@12Checklist:
@nestjs/passport/dist/...) with root imports.defaultStrategy / property from anything you return out of getAuthenticateOptions().@nestjs/common on ^11 or ^12.One column per quarter.
fix: exclude last argument only if its of type function (cb)
fix: remove redundant exclude unknown type
fix: use all ctor params type to include overloads #1857
Nothing published for this version
Nothing published for this version
v11.0.0 #1641 #1439
Merge pull request #1455 from nestjs/renovate/cimg-node-21.x
Merge branch 'master' of https://github.com/nestjs/passport
Merge pull request #1386 from gaiuaurelian/fix/1385
Merge pull request #1294 from nestjs/renovate/npm-vm2-vulnerability
Merge pull request #1160 from nestjs/renovate/npm-http-cache-semantics-vulnerability
chore(deps): update nest monorepo to v9.3.5
chore: update hooks to use no-install
files field in package.json to only include dist files (54fd65e)Merge pull request #959 from nestjs/renovate/major-nest-monorepo
context parameter on IAuthGuard (28bee04)chore(deps): update typescript-eslint monorepo to v5.28.0
fix(): fallback to empty options object if not provided
Merge pull request #824 from jmcdo29/fix/property-injection-optional
Merge pull request #808 from nestjs/renovate/npm-ansi-regex-vulnerability
Merge pull request #657 from nestjs/renovate/npm-path-parse-vulnerability
Merge pull request #647 from Dzixxx/promise-handling-in-get-auth-options
chore(deps): update dependency @types/passport to v1.0.7
Merge pull request #603 from nestjs/renovate/npm-glob-parent-vulnerability
Merge branch 'master' of https://github.com/nestjs/passport
Merge branch 'master' of https://github.com/nestjs/passport
Merge pull request #440 from egormkn/verify-length
fix(): add additional validate existance check
Merge pull request #205 from p-m-p/master
Merge pull request #323 from xyide/master
Merge pull request #219 from nestjs/renovate/major-nest-monorepo
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →