NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2367 most downloaded on npm
Modern and scalable routing for React applications
Last release 4 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
638 releases · first in 2025
One column per month.
Updated dependencies [ d521abd ]:
#8127 41ebd28 - fix: use http scheme for sitemap xmlns per sitemaps.org spec
#8533 05223c2 - Defer sitemap and XML dependencies until sitemap generation is enabled to reduce Start plugin startup work.
Updated dependencies [d521abd]:
Updated dependencies [ 488d046 , e81845f , 0c1b5e3 , 3cdd1af ]:
#8297 488d046 - Update seroval and seroval-plugins from 1.6.2 to 1.6.7. This picks up the typed array length guard, the maxBase64Length and compactArrayBufferViews options, and the isStream export.
Updated dependencies [488d046, e81845f, 0c1b5e3, 3cdd1af]:
Patch Changes #8202 222300b - Fix the Rsbuild Start manifest dropping every route's stylesheets and preloads on Windows by normalizing rspack module p
Updated dependencies [`cecae54`, `0103578`, `ce10dcd`, `84936cc`, `bbd2336`]:
Updated dependencies [`bc80866`, `e561fa1`, `cbbfbe3`, `a1c8d1a`, `cbbfbe3`, `a0b2ad9`, `1ca361b`]:
#8204 cbbfbe3 - Reduce per-request SSR overhead: abort settled route matches with one shared AbortError-shaped reason instead of building a stack-capturing DOMException per match, skip JSON.parse for search values that cannot start JSON, wait on request signals with one listener per wait, and keep resolved server-function modules in production builds instead of re-importing them on every call.
Updated dependencies [bc80866, e561fa1, cbbfbe3, a1c8d1a, cbbfbe3, a0b2ad9, 1ca361b]:
Patch Changes #8397 ab99818 - Support Rsbuild 2.2: preserve function-based Rspack watch exclusions and regular-expression flags when adding monorepo b
Updated dependencies [ d76a332 , b747fb8 , 6cfb1e8 , 700a714 , 700a714 , 7e349c3 , 873c830 , 7e349c3 , 634da91 , e9396c9 , 634da91 , f151ab0 , bc57fa3
d76a332, b747fb8, 6cfb1e8, 700a714, 700a714, 7e349c3, 873c830, 7e349c3, 634da91, e9396c9, 634da91, f151ab0, bc57fa3, 9872d2a, d76a332, 634da91, 634da91, 7e349c3, 9448caa, e9396c9, 700a714, 634da91, 634da91]:
Updated dependencies [ d914b08 ]:
d914b08]:
Preserve native form HTTP redirects, route error handling and masks for document redirects, and per-navigation destinations for shared loader redirect
#8300 49bcd4d - Refresh compatible build and runtime dependencies.
#8308 9c1871c - Validate navigation and redirect destinations, keep ambiguous relative URLs on the current origin, and constrain prerender requests and output paths. Prevent redirect headers from appearing in serialized server function response bodies.
Preserve native form HTTP redirects, route error handling and masks for document redirects, and per-navigation destinations for shared loader redirects. Avoid redundant origin parsing and reduce link styling and server-rendering work. Configured origins must already be normalized.
Keep blocked-link inactive props consistent during React hydration, honor explicit redirect Location headers before checking route options, and refresh Vue link state when destinations become internal. Reuse the protocol-relative URL check while parsing redirect schemes once.
Reduce React link bundle size by sharing pathname comparisons, state-prop selection, and element creation.
Share normalized pathname comparisons in Solid and Vue links to reduce bundle size.
#8261 919c397 - Avoid unused build indexes and skip CSS content capture when inline CSS is disabled in Vite and Rsbuild.
Updated dependencies [f9836f1, 49bcd4d, 9c1871c, 9871c06, 0654c0a]:
Updated dependencies [ edf0e16 , 2f20c00 , 28a5e45 , 08eff50 , 216c0c4 , 2f91503 , f0b5eda , 50eafca , 0497cae , ee28348 , c18e690 ]:
#8164 37877da - Improve Rsbuild import protection performance by scanning the compilation graph once and deferring diagnostic work until a violation is found.
#8251 0497cae - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.
Updated dependencies [edf0e16, 2f20c00, 28a5e45, 08eff50, 216c0c4, 2f91503, f0b5eda, 50eafca, 0497cae, ee28348, c18e690]:
Updated dependencies [ fa65287 , cb281d7 ]:
#8135 a0041bb - Migrate the Rsbuild client chunk configuration to the v2 splitChunks option while preserving async-only chunk splitting.
Updated dependencies [fa65287, cb281d7]:
Updated dependencies [`3e016ac`]:
3e016ac]:
Updated dependencies [`5d3785d`, `63d2cc9`]:
Updated dependencies \[`4c89b15`, `cf6ab17`, `bdaf73a`]:
Updated dependencies \[`31882c7`]:
31882c7]:
Updated dependencies \[`7e93431`]:
7e93431]:
Updated dependencies \[`51138a8`]:
51138a8]:
Updated dependencies \[`44a8c3e`, `5253e70`]:
@tanstack/start-server-core@1.169.23
Updated dependencies \[`ea3a665`]:
ea3a665]:
Updated dependencies \[`84db4a8`, `9cac62a`, `6aefb33`]:
Updated dependencies \[`b2908c6`]:
Updated dependencies \[`45c4ad8`]:
45c4ad8]:
### Patch Changes - #8117 `3e016ac` - optimize buildLocation path resolution skip building search validation when disabled skip location state sharing
3e016ac - optimize buildLocation path resolution https://github.com/TanStack/router/pull/8108
skip building search validation when disabled https://github.com/TanStack/router/pull/8112
skip location state sharing when impossible https://github.com/TanStack/router/pull/8110
fix cache hits for mask resolution when entry is null https://github.com/TanStack/router/pull/8111### Patch Changes - #8084 `5d3785d` - preserve pending UI across retained routes - #8092 `63d2cc9` - Render route errors when redirect target construc
Nothing published for this version
### Patch Changes - #8071 `4c89b15` - inline getOpenAndCloseBraces in parseSegment for byte shaving - #8069 `cf6ab17` - inline isFunction utility fn f
49f6863]:
### Patch Changes - #8054 `31882c7` - Reuse resolved lazy route components when revisiting code-split routes, preventing unnecessary pending UI.
ffdd64e - Preserve exact Vite-resolved module IDs, including virtual prefixes and query variants, when the Start compiler recursively loads imports. Clean IDs only for file-oriented diagnostics and invalidation, and preserve existing query strings when adding compiler-owned lookup flags, so virtual modules such as import-protection mocks reach their plugin load hooks unchanged.### Patch Changes - #8039 `7e93431` - load-client can cache settles abandonned loader work without preload authority
78dd1a6]:
### Patch Changes - #8019 `51138a8` - handle excessive parent relative links
e56a677]:
### Patch Changes - #8006 `44a8c3e` - skip impossible JSON parse attempts - #8010 `5253e70` - perf: speed up structural sharing (replaceEqualDeep) by
#8010 5253e70 - perf: speed up structural sharing (replaceEqualDeep) by computing enumerable own keys with Object.keys + a length compare instead of getOwnPropertyNames followed by a propertyIsEnumerable call per key. This runs on every selector result on every state update when defaultStructuralSharing is enabled, and is ~1.3-1.5x faster on typical router state objects with identical behavior.
e2dd204]:
### Patch Changes - #7992 `ea3a665` - retain mounted UI during revalidation
9809a06]:
RouterCore.getMatchedRoutes() now returns [matchedRoutes, rawParams, foundRoute] instead of an object.
#7984 84db4a8 - Improve route-tree construction and matching performance by fusing static and
dynamic node creation, sorting only dynamic sibling lists that need it, and
deriving matcher depth from trie nodes.
#7985 9cac62a - perf: compact private bundle boundaries- #7975
#7967 6aefb33 - Preserve path params in their raw string form while matching routes so structured values returned by params.parse produce stable match IDs and do not reuse stale loader data.
RouterCore.getMatchedRoutes() now returns [matchedRoutes, rawParams, foundRoute] instead of an object.
Updated dependencies [9cac62a]:
### Patch Changes - #7962 `b2908c6` - Update Seroval dependencies to version 1.6.2.
Invalidation now retires matching active preloads so older speculative loader results cannot become fresh cache data after invalidation.
#7805 45c4ad8 - Rewrite match loading around a lane-based scheduler that tracks each navigation, preload, and background reload as an ordered unit of work. This fixes pending/redirect/retry state leaking between overlapping navigations, restores correct SSR status codes for redirects, errors, and not-found responses, and closes hydration gaps where the client re-ran work the server had already completed.
headers() now only runs on the server, matching the documented behavior — it is no longer invoked during client-side asset projection.gcTime and preloadGcTime now match the existing runtime default of 5 minutes (300_000).Removed / changed exported internals
RouterState no longer includes loadedAt, isTransitioning, statusCode, or redirect. Use match.updatedAt in place of loadedAt; subscribe to router.state.status / router.state.isLoading in place of isTransitioning; server response status and redirect handling are now internal to the server loader and are no longer exposed on router.state.RouteMatch.fetchCount has been removed, with no replacement — it was purely informational.RouteMatch.status no longer includes 'redirected' (it remains 'pending' | 'success' | 'error' | 'notFound') — redirected matches are dropped from the match list instead of being rendered.RouteMatch.globalNotFound has been renamed and privatized to the internal _notFound field. Use match.status === 'notFound' instead.Match components now accept routeId instead of matchId.RouterStores adapter contract now uses route-keyed presentation stores: matchesId is replaced by ids, matchStores by byRoute, and getRouteMatchStore() by getMatchStore(). The separate loadedAt, isLoading, isTransitioning, statusCode, and redirect stores have been removed, along with the pending/cache stores and their setters. StoreConfig.init has also been removed. Read application-facing state from router.state; preload and cache coordination are now internal.RouterCore members getMatch(), updateMatch(), cancelMatch(), and cancelMatches() — read matches from router.state.matches (e.g. router.state.matches.find((m) => m.id === id)); there is no replacement for mutating or cancelling an individual in-flight match from outside the router.RouterCore.hasNotFoundMatch() — use router.state.matches.some((m) => m.status === 'notFound').RouterCore.looseRoutesById — use routesById.RouterCore.isPrerendering(), RouterCore.isViewTransitionTypesSupported, and RouterCore.viewTransitionPromise, with no replacement.RouterCore.getParsedLocationHref() and RouterCore.clearExpiredCache(), with no replacement — expired cache entries are now reconciled automatically as part of match commit.RouterCore.latestLoadPromise and RouterCore.beforeLoad(), with no replacement.RouterCore.commitLocationPromise and RouterCore.pendingBuiltLocation have been replaced by the internal _commitPromise and _pendingLocation fields.GetMatchFn and UpdateMatchFn types, along with the methods they typed.getMatchedRoutes() export from @tanstack/router-core — use the router.getMatchedRoutes() instance method instead.RouterCore.loadRouteChunk() no longer accepts an array of component types as its second argument. One-argument usage is unchanged; the optional second argument is now 'errorComponent', 'notFoundComponent', or false for internal boundary loading.Redirect.redirectHandled, which was internal redirect bookkeeping.MatchRoutesOpts.preload and MatchRoutesOpts.dest have been removed.StartTransitionFn is now (fn, expected) => Promise<boolean> (previously (fn) => void). This only affects custom framework adapters that implement startTransition.776d8ef]:
Updated dependencies [`df1076c`, `837897f`]:
Updated dependencies [`ac10815`]:
ac10815]:
Updated dependencies [`301f6ba`, `2cca73c`, `7a83e67`, `76b3d3b`]:
#7552 301f6ba - Fix Start compiler handling for TS-wrapped server/env-only function calls and safely remove unused imported server function handlers from client output.
Updated dependencies [301f6ba, 2cca73c, 7a83e67, 76b3d3b]:
### Patch Changes - #7540 `8091918` - Fix Rsbuild RSC builds so client directives in packages under node_modules are compiled and detected correctly.
Updated dependencies [`b4cd5af`]:
b4cd5af]:
Updated dependencies [`9cb7a00`]:
Updated dependencies [`2f53749`]:
2f53749]:
Updated dependencies [`d1997b6`]:
d1997b6]:
Updated dependencies [`9c09bca`]:
#7501 9c09bca - fix(start): emit client entry scripts from the root route manifest. When scriptFormat: 'iife' and the entry chunk has static-import siblings (e.g. an extracted runtime via optimization.runtimeChunk: 'single'), the manifest now includes those async siblings before the async client entry in root route scripts, fixing hydration for IIFE bundles with extracted runtimes.
Updated dependencies [9c09bca]:
Fix serialization adapter module resolution in TanStack Start. Vite dev now uses clean runtime-specific virtual module IDs instead of browser requests
Fix serialization adapter module resolution in TanStack Start. Vite dev now uses clean runtime-specific virtual module IDs instead of browser requests containing encoded null-byte virtual IDs, which avoids reverse proxy failures. When no serialization adapters are configured, Vite and Rsbuild now resolve #tanstack-start-plugin-adapters through the package empty-adapter fallback. (#7484)
Publish matching TanStack Start dev server packages so fresh installs do not pair a Start plugin that no longer provides tanstack-start-injected-head-scripts:v with an older Start server runtime that still imports it. (#7487)
Updated dependencies [a82cec6, d8be4f8]:
Add Vite bundled dev mode support for TanStack Start. Start now recognizes Vite's experimental.bundledDev opt-in, uses the bundled dev client entry in
experimental.bundledDev opt-in, uses the bundled dev client entry in the dev manifest, keeps server requests pointed at the latest client build output, and preserves import-protection behavior for bundled client dev. (#7482)Add support for Rsbuild client output formats, including module output by default and IIFE output for classic script environments.
Add support for Rsbuild client output formats, including module output by default and IIFE output for classic script environments. (#7477)
Client entry scripts and preloads are now represented as root route manifest assets, script preloads follow the manifest script format, and script asset cross-origin configuration uses the script key. The transformAssets script callback context now exposes only kind: 'script' and url, keeping script format handling internal to manifest rendering.
Fix Rsbuild server function metadata replay when Rspack restores modules from its persistent cache. (#7477)
Server function metadata is now stored on Rspack module build info and replayed from cached modules before resolver modules are rebuilt, preventing warm restarts from losing server function registrations.
Updated dependencies [51a97a1]:
Updated dependencies [`5268ba4`]:
5268ba4]:
Updated dependencies [`7df0d02`]:
7df0d02]:
Updated dependencies [`0300f87`, `0300f87`]:
Add deferred Hydrate boundary support for TanStack Start.
Add deferred Hydrate boundary support for TanStack Start. (#7362)
Hydrate boundaries can now be code-split by the Start compiler, preload their generated client chunks, preserve server-rendered fallback HTML, and replay interaction-triggered events after hydration. The compiler integration now uses a Start-owned compiler plugin for Hydrate virtual modules across Vite and Rsbuild, with dev invalidation for generated virtual modules.
Shared AST utilities used by the router code-splitter and Hydrate virtual modules were moved into @tanstack/router-utils so both pipelines can retain referenced top-level declarations, unwrap local exports, and let dead-code elimination remove unused route module code.
Updated dependencies [`b60eb36`]:
b60eb36]:
Updated dependencies [`8146db7`]:
8146db7]:
Updated dependencies [`d9cf933`]:
d9cf933]:
Updated dependencies [`d533f87`]:
d533f87]:
Updated dependencies [`742941e`]:
742941e]:
Add runtime-configurable inline CSS and opt-in CSS URL templates for transformAssets.
add createCsrfMiddleware based on Sec-Fetch-Site header, auto-apply to unconfigured servers, warn for others
add createCsrfMiddleware based on Sec-Fetch-Site header, auto-apply to unconfigured servers, warn for others (#7373)
Updated dependencies [b1c061a, 038cd12, 201e150, 5ae2ae5]:
Updated dependencies \[`b2908c6`]:
c5811aa]:
Updated dependencies \[`45c4ad8`]:
45c4ad8]:
Your coding agent can read these notes before it upgrades. Set up the MCP server →