NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3338 most downloaded on npm
Cypress is a next generation front end testing tool built for the modern web
Last release 5 days ago
29 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
11 years old
294 releases · first in 2015
Changelog: https://docs.cypress.io/app/references/changelog#16-1-1
Released Sep 29, 2026
Performance:
Bugfixes:
Misc:
TypeScript now accepts an options object on six commands that already accepted one at runtime: .nextUntil() , .parentsUntil() , and .prevUntil() take options in place of the filter argument; .each() and .spread() take options before the callback; and .scrollIntoView() takes an offset that sets a single axis, leaving the other at 0. These calls previously reported a type error. Addressed in #34886 .
TypeScript now accepts every function cy.clock() can override in the browser, such as requestAnimationFrame , requestIdleCallback , performance , Intl , and queueMicrotask , and accepts null as the first argument, as in cy.clock(null, ['setTimeout', 'clearTimeout']) . These calls previously reported a type error. The tick() method on the yielded clock is now typed as returning the clock's new time in milliseconds instead of void . Addressed in #34912 .
TypeScript now types the docsUrl property on the error passed to an uncaught:exception handler as string | string[] . An uncaught exception carries the docs url for your application's error alongside the Cypress one, so docsUrl can hold more than one url at a time. Addressed in #34879 .
TypeScript now types the third argument of a .each() callback on DOM elements as the jQuery collection being iterated, which is what Cypress passes at runtime, instead of an array of elements. Addressed in #34933 .
The error shown when .clear() is called on an element it can't clear now lists the elements .clear() accepts: a <textarea> , a text-like <input> such as text , email , or number , or an element made editable by contenteditable or designMode . Addressed in #34914 .
The error shown when a .each() or .spread() callback both runs Cypress commands and returns a synchronous value now names the command you called and links to its documentation, instead of saying that cy.then() failed. The same error from .then() now links to the .then() documentation. Addressed in #34933 .
When a command runs after your application navigates to another subdomain of the same domain outside of cy.origin() , the error now explains that, while injectDocumentDomain is disabled (the default), a subdomain counts as a different origin, so commands run there also need cy.origin() . This explanation was intended to appear but never did. Addressed in #34930 .
The TypeScript documentation for the multiple option of .dblclick() now shows its default as true , matching how .dblclick() behaves. Addressed in #34929 .
cy.contains() now shows as a parent command in the Command Log when it starts a chain, as in cy.contains('Save') . It previously always showed as a child command, with a - before its name, as if it were chained off the command before it. Addressed in #34939 .
Dependency Updates:
Upgraded axios from 1.15.2 to 1.20.0 to address Prototype Pollution (CVE-2026-44494), NO_PROXY Bypass (CVE-2026-44492), Header Injection (CVE-2026-44490), and ReDoS (CVE-2026-44496) vulnerabilities reported in security scans. Also upgraded form-data from 4.0.5 to 4.0.6 , the minimum version axios 1.20.0 requires, which addresses a CRLF Injection (CVE-2026-12143) vulnerability reported in security scans. Addresses #34863 .
Upgraded proxy-addr from 2.0.7 to 2.0.8 to address a User Impersonation (CVE-2026-90711) vulnerability reported in security scans. Addresses #34858 .
One column per quarter.
Changelog: https://docs.cypress.io/app/references/changelog#16-1-0
Released Sep 15, 2026
Performance:
Features:
Bugfixes:
cypress tap run now reports that the spec is running and to use cypress tap status for progress, instead of printing the launched spec's testing type and browser. #34777 .
Fixed a regression in 16.0.0 where a run in Chrome, Chromium, or Edge could stop producing output partway through and hang indefinitely, with no error, no failing test, and no timeout, until the CI job was killed for exceeding its no-output limit. Fixes #34778 .
Fixed an issue where adding a --disable-features argument in before:browser:launch silently dropped every feature Cypress disables in Chrome, Chromium, and Edge, because the browser honors only the last occurrence of that argument. Cypress now merges its own values with yours. Fixes #34775 .
Fixed a regression in 16.0.0 where, in cypress open on Chrome, Chromium, and Edge, testing a site that registers an origin-wide service worker could render the site's own content — such as its 404 page — in place of the Cypress app after clicking a spec or reloading the browser tab. A service worker registered by the site under test can no longer answer for Cypress's own pages and assets. Fixes #34789 . Addressed in #34762 .
Fixed an issue where a variant of A/B tested content in the Cypress app that was weighted never to be shown could become the only variant shown. Fixes #34814 .
Fixed a regression in 12.0.0 where an assertion on a cy.contains() command that matched no element did not say what was searched for, reporting expected undefined not to exist in the DOM in the Command Log. The searched content is now shown, such as expected Saving not to exist in the DOM . Fixes #25962 .
Fixed a regression in 16.0.0 where blockHosts was not enforced in Chrome, Chromium, and Edge. Requests to a blocked host reached the network instead of failing with a 503 status. Scripts and other resources from those hosts still loaded. Fixes #34785 .
Fixed a regression in 16.0.0 where the headless Electron browser window was sized smaller than requested on Windows during cypress run , so failure screenshots and recorded videos were smaller than the expected 1280x720. Setting preferences.width and preferences.height in before:browser:launch had no effect on the result. Fixes #34771 .
Misc:
Fixed an issue where setting keystrokeDelay in a TypeScript configuration file failed to compile with 'keystrokeDelay' does not exist in type 'ConfigOptions' , even though Cypress read and validated the option at runtime. Fixes #34796 . Addressed in #34798 .
When a Test Replay recording fails while being prepared for a spec during cypress run , Cypress now recommends increasing available disk space and confirming that the temporary directory used for Test Replay recordings is readable and writable, instead of printing only the underlying error such as SqliteError: unable to open database file . Addressed in #34763 .
Changelog: https://docs.cypress.io/app/references/changelog#16-0-0
Released Sep 1, 2026
Summary
Faster tests, less flake, and a few breaking changes that may require updates.
Most of this release's speed arrives without you editing a single test: requests run over HTTP/2 by default in Chrome, Chromium, and Edge browsers, cy.type() drops its 10ms keystroke delay, visibility checks use a faster algorithm, cookie and storage commands now retry the way queries do, and browser memory management is on by default so long runs stop crashing partway through. Read the full Cypress 16 announcement for what changed and why.
Breaking Changes:
info
Refer to the 16 Migration Guide for help migrating your code. The upgrade guide also includes a ready-made prompt for your AI assistant to assist you with the upgrade.
Chrome, Chromium, and Edge intercept test traffic on the native browser network rather than routing it through Cypress. A small number of cy.intercept() behaviors differ as a result. Most notably, req.httpVersion is no longer reported, and compression headers are no longer present on an intercepted response. Firefox, WebKit, and Electron continue to use the legacy network path, and forceHttp1 routes every browser back through it while you migrate. See Native network interception and the Migration Guide . Addresses #3708 .
Removed support for Node.js 20 and Node.js 25. Cypress now requires Node.js 22.x, 24.x, or >=26.x. Addresses #33705 and #33778 .
Upgraded the bundled Node.js version from 22.19.0 to 24.15.0 . Addressed in #33494 .
Removed Cypress.env() . Use Cypress.expose() for non-sensitive values that need to be readable in the browser, and cy.env() for sensitive values that must remain in the Node process. The env key is no longer supported in per-test or suite config overrides; use expose: { KEY: value } instead if absolutely necessary. The allowCypressEnv configuration option has also been removed. See the Migration Guide . Addresses #33889 . Addressed in #33963 .
Removed the cy.exec() command and the execTimeout configuration option, both deprecated in Cypress 15.21.0 . Use cy.task() and taskTimeout instead — a task runs in Node without depending on the operating system, shell, or terminal of the machine running Cypress. Calling cy.exec() now throws, and setting execTimeout prints a warning and is otherwise ignored. See the Migration Guide . Addresses #34694 .
Removed the cy.end() command, which ended a chain of commands by yielding null . A Cypress chain is already terminated when the next cy.<command>() starts a new chain, so existing .end() calls can simply be removed. See the Migration Guide . Addressed in #33696 .
The experimentalMemoryManagement configuration option has graduated out of experimental status and been replaced by manageBrowserMemory , which defaults to true . Memory management is now enabled by default in Chromium-based browsers. Setting experimentalMemoryManagement prints a warning and is otherwise ignored. If you previously set experimentalMemoryManagement: false to opt out, you must now set manageBrowserMemory: false . See the Migration Guide . Addresses #34385 .
Removed the experimentalSourceRewriting configuration option. The default regex-based source rewriting handles every case the AST-based rewriter did, so default behavior is unchanged and the option can be deleted from your config. If you were using it to work around Subresource Integrity errors, enable removeSRIAttributes instead. See the Migration Guide . Addresses #34213 .
The default keystrokeDelay for cy.type() has been changed from 10 to 0 to improve performance of typing-heavy test runs. Users who relied on the implicit 10ms delay can restore it by setting keystrokeDelay: 10 in their Cypress configuration or via Cypress.Keyboard.defaults() . Addresses #33523 .
The experimental experimentalFastVisibility flag has been replaced by a new visibilityStrategy configuration option that accepts 'legacy' or 'modern' and defaults to 'modern' . The modern visibility algorithm (based on the browser's native Element.checkVisibility() API) is now the default for all users. visibilityStrategy is deprecated, so set visibilityStrategy: 'legacy' only as a temporary migration path. See the Visibility Strategy guide for migration help. Addressed in #33794 .
cy.getCookie() , cy.getCookies() , and cy.getAllCookies() are now retry-able query commands . They re-read cookies and retry any chained assertions until they pass or time out, are governed by defaultCommandTimeout , and can no longer be overwritten with Cypress.Commands.overwrite() . Use Cypress.Commands.overwriteQuery() instead. See the Migration Guide . Addresses #4802 .
viewportWidth and viewportHeight can no longer be set via Cypress.config() during test execution. Setting them this way affected the next test rather than the current one and was not reflected in Test Replay. Use cy.viewport() or set them in the test configuration of a describe , context , or it block instead. See the Migration Guide . Addresses #31592 . Addressed in #34262 .
blockHosts can no longer be set via Cypress.config() during test execution. Setting it this way affected the next test rather than the current one. Set blockHosts in the test configuration of a describe , context , or it block instead. See the Migration Guide . Addressed in #34553 .
cy.getAllLocalStorage() and cy.getAllSessionStorage() are now retry-able query commands . They re-read storage from all origins and retry any chained assertions until they pass or time out, accept a timeout option governed by defaultCommandTimeout , and can no longer be overwritten with Cypress.Commands.overwrite() . Use Cypress.Commands.overwriteQuery() instead. See the Migration Guide . Addresses #26422 . Addressed in #34318 .
The cypress info command no longer prints proxy environment variables ( HTTP_PROXY , HTTPS_PROXY , NO_PROXY ) or CYPRESS_* environment variables, so its output is safe to paste into a bug report. The command now reports only Cypress-specific details such as file paths, version, and system information. Addresses #34103 . Fixed in #34314 .
Removed built-in CoffeeScript support. The default @cypress/webpack-batteries-included-preprocessor no longer bundles coffee-loader or coffeescript , and .coffee is no longer resolved for specs, support files, or cy.fixture() . Use JavaScript or TypeScript, or add CoffeeScript to your own webpack config via @cypress/webpack-preprocessor . See the Migration Guide . Addressed in #33654 .
Component Testing breaking changes:
Angular
Removed support for Angular 18, 19, and 20. The minimum supported version is now 21.0.0 . Addresses #33005 , #33655 , and #33656 .
cypress/angular-zoneless has been merged upstream into cypress/angular . In a corresponding change, the @cypress/angular-zoneless npm package is deprecated and no longer supported and cypress/angular-zoneless is no longer shipped with the Cypress binary. Addresses #33007 .
The zoneless testing harness is now the default in cypress/angular . zone.js is no longer required to be installed for your Cypress project.
@angular/platform-browser-dynamic has been replaced with @angular/platform-browser . Addresses #33006 .
autoSpyOutputs and autoDetectChanges have been removed from cypress/angular .
@cypress/schematic now requires cypress ^16.0.0 , @angular/cli >=21.0.0 and @angular/core >=21.0.0 , and no longer scaffolds the cypress/angular-zoneless mount handler. Addresses #33007 .
Vite
Removed support for Vite 5, Vite 6, and Vite 7 when using the Vite dev server for component testing. The minimum supported Vite version is now 8.0.0 . Upgrade Vite (and any @vitejs/* plugins that pin older major versions) before upgrading Cypress. Addresses #33724 , #33725 , and #33726 .
Next.js
Removed support for Next.js 14. Next.js 15.0.4+ or 16+ is now required. Addressed in #33641 .
Deprecations:
Deprecated the Electron browser as a test browser. The Electron browser will be removed in a future major version of Cypress; switch to Chrome or another installed browser to avoid a breaking change when you upgrade. See Migrating away from the Electron browser . Addresses #33560 . Addressed in #34074 .
Added the forceHttp1 configuration option, which routes every browser through the legacy network path. It is deprecated at introduction and prints a warning when set: it exists to give suites time to migrate to the native browser network, and will be removed once that path is supported long term in both Chrome and Firefox. Addresses #33847 .
Features:
Cypress now supports HTTP/2/3 in Chrome, Chromium, and Edge. Your application is tested over the same protocol it uses in production, with multiplexed requests and no six-connection ceiling, so modern apps load faster under test and behave the way your users actually experience them. Cypress also stops terminating TLS for the application under test, so the browser validates your origin's real certificate instead of one Cypress generates. See Native network interception and the Migration Guide . Addresses #3708 .
Angular version 22 is now supported within component testing, including Launchpad project detection and the @cypress/schematic Angular CLI integration. Addresses #33753 .
Bugfixes:
Fixed an issue where Firefox tests could intermittently fail with errors like Cannot get AUT url: no AUT context initialized when a command ran while Cypress was still identifying the application frame — for example right after a reload, a navigation, or moving to the next spec. Cypress now waits for the frame to be identified, and re-derives it if the browser event announcing it was missed. Fixes #34705 .
Fixed an issue where a run in which every test passed could still exit with code 1 , indistinguishable from a single failing test. Cleanup that fails or takes too long while Cypress shuts down no longer changes the exit code, and is reported in the run output instead. Fixed in #34686 .
Fixed an issue where the after:run event handler would not run when a project was closed in cypress open mode and experimentalInteractiveRunEvents was set. Addressed in #34700 .
Fixed an issue where a single cleanup step that stalled while Cypress shut down, such as waiting on a browser that was slow to close, could hold up the rest of shutdown. Addressed in #34699 .
Fixed an issue where cypress tap specs and cypress tap run failed against a Cypress session whose project sets the internal namespace configuration option, reporting that the session was older than the CLI when it was not. Addresses #34660 .
Dependency Updates:
Upgraded electron from 37.6.0 to 41.7.0 .
Upgraded bundled Chromium version to 146.0.7680.216 .
Upgraded dayjs from 1.10.4 to 1.11.23. Date comparisons are significantly faster, reducing background work while a run is in progress. Addressed in #34748 .
Fixed an issue where Chrome and Firefox offered to translate the application under test, showing a translation prompt during the run. Fixes #34662 .
Released Aug 25, 2026
Bugfixes:
Fixed an issue where Chrome and Firefox offered to translate the application under test, showing a translation prompt during the run. Fixes #34662 .
Fixed an issue where every cypress tap command printed HTTP request lines, such as GET /__cypress/sessions/<id> , to the terminal of the cypress open session it attached to, burying that session's own output. Fixes #34668 .
Changelog: https://docs.cypress.io/app/references/changelog#15-21-0
Released Aug 18, 2026
Deprecations:
Features:
Added the cypress tap command, which gives your AI agent direct access to your open-mode Cypress session. It lists the open-mode Cypress sessions running on the machine, starts and reruns a spec, reports a run's status and results, prints a failing test's error and Command Log, and inspects the DOM and accessibility tree of the application under test. Every subcommand prints readable output by default and machine-readable JSON with --json . Run cypress tap --help for the full list of subcommands. Addresses #34036 .
Added a CYPRESS_DISABLE_GUEST_TELEMETRY environment variable, which disables any reporting Cypress sends for non-logged sessions. This includes anonymous usage events within Cypress open-mode and the Cypress CLI. Addressed in #34540 .
Bugfixes:
Fixed an issue where WebKit runs could hang indefinitely when more parallel requests than the browser's per-host connection pool were intercepted by a cy.intercept() route with a request handler. Fixes #33926 and addresses #23807 .
Fixed an issue where overriding blockHosts with test configuration (for example describe('...', { blockHosts: [...] }, ...) ) had no effect, so requests were still blocked or allowed according to the project-level value. Test-level blockHosts overrides now take effect at runtime and are restored between specs. Fixes #21151 .
Fixed an issue where cypress run printed the (Attempt N of M) line twice for the same attempt when a beforeEach and an afterEach hook both failed during that attempt. Fixes #26143 .
Fixed an issue where passing an object to the have.attr , have.css , or have.prop assertions , such as .should('have.css', { backgroundColor: 'rgb(128, 0, 0)' }) , applied those styles, attributes, or properties to the element and passed instead of asserting on them. These assertions now fail with an error stating that the name must be a string. Fixes #26451 .
Fixed an issue where the console props output for a cy.env() command listed the requested environment variable names under numbered keys instead of a single Env vars label. Addressed in #34615 .
Fixed an issue on Windows where adding, renaming, moving or deleting a spec file while cypress open was running was not reflected in the specs list, leaving stale specs until Cypress was restarted. Clicking a spec that had been renamed or moved could then fail to run. Projects whose specPattern contains a directory, such as the End-to-End Testing default cypress/e2e/**/*.cy.{js,jsx,ts,tsx} , were affected. Fixes #22303 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-20-1
Released Aug 10, 2026
Bugfixes:
Fixed a regression in 15.20.0 where the Cypress app sent all Cypress Cloud requests to http://localhost:3000 instead of Cypress Cloud. Logging in could not complete, and the Runs and Debug pages reported no data. Addressed in #34536 .
Fixed a regression in 15.18.0 where pinning a command in the Command Log could leave the AUT snapshot permanently blank, with the pin stuck on. Stopping a run in open mode also no longer clears the AUT. Addressed in #34502 .
Misc:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-20-0
Released Aug 4, 2026
Performance:
Fixed an issue where visibility checks (such as .should('be.visible') and actionability) serialized an element's entire text subtree once per overflow-hidden ancestor, which on text-heavy pages could exhaust the renderer's memory and crash it ( We detected that the Chrome Renderer process just crashed ). Fixes #34329 .
Reduced the sampling overhead of experimentalMemoryManagement when Cypress runs inside a memory-limited container using cgroup v1. Memory readings no longer spawn helper subprocesses on every sampling interval, which lowers CPU usage that previously competed with the tests, most noticeably on constrained CI machines. Addresses #34105 . Fixed in #34331 .
Features:
scrollBehavior now accepts a per-axis value, such as { block: 'start', inline: 'nearest' } , so the vertical and horizontal alignment used to scroll an element into view before an action command can be set independently. The per-axis form takes the same values as the native scrollIntoView : 'start' , 'end' , 'center' , and 'nearest' . A single value also accepts the new 'start' and 'end' alignments, which align both axes at once. See Scrolling . Addresses #34460 . Addressed in #34474 .
cy.request() and cy.intercept() now accept the HTTP QUERY method. Previously it was rejected as an invalid method in the browser. Fixes #28282 .
Bugfixes:
Fixed a regression in 15.18.1 where action commands scrolled an already-visible element's container horizontally. The scrollBehavior values 'top' and 'bottom' revert to aligning only the vertical axis; use 'start' or 'end' to align both. Fixes #34460 .
Fixed a regression in 15.19.0 where commands that read from the application under test, such as cy.url() , cy.title() and cy.reload() , targeted the command log instead of your application when the application set window.name . Fixes #34435 .
Fixed an issue where a cy.* command error message that interpolated a value containing a $ character could render incorrectly, with a leaked {{...}} placeholder or duplicated or dropped surrounding text. Such values are now inserted verbatim. Fixed in #34221 .
Fixed an issue where a Cypress error message that interpolated a value containing a $ sequence (such as $& , $` , $' , or $$ ) could render with corrupted or duplicated text. Such values are now shown verbatim. Fixed in #34220 .
Fixed an issue where cy.intercept() matching on the auth option compared only the portion of a Basic authentication password before the first colon, so a request whose password contained a colon (permitted by RFC 7617) failed to match. The full password is now compared. Fixed in #34206 .
Fixed an issue where cy.intercept() routes specifying a numeric port (for example port: 8080 or port: [8080] ) did not match requests on non-default ports. Such routes now match as documented. Fixes #17653 . Fixed in #34205 .
Fixed an issue where inline source maps embedded without a charset (for example those emitted by esbuild) were not decoded and were silently dropped. These inline source maps are now decoded. Fixed in #34204 .
Fixed an issue where the TypeScript 7 support added in 15.18.0 did not work: TypeScript spec and support files failed to compile with Error: Cannot find module '@babel/preset-typescript' . Fixes #34359 .
Fixed an issue where a cy.origin() block could intermittently fail with TypeError: Cannot read properties of undefined (reading 'applied') , incorrectly reported as originating from your test code. Addressed in #34376 .
Fixed an issue where, during a cy.origin() block, session cookies set on the primary origin by the first page visited in a test were not included in the identity provider's callback request back to the primary origin (for example, POST /auth/callback in an OAuth Authorization Code flow). Fixes #29719 . Fixed in #34287 .
Fixed an issue where the configuration validation error shown when passesRequired is omitted from the experimental detect-flake-and-pass-on-threshold retry strategy reported the value of an unrelated option instead of the passesRequired value. Fixed in #34202 .
Fixed an issue where the configuration validation error for an absolute ca filepath in clientCertificates referenced the wrong certificate. Fixed in #34201 .
Fixed an issue where HTTP 3xx responses (such as 304 Not Modified ) were shown with a failed (red) indicator in the Command Log. These responses now display as successful. Fixes #34066 . Fixed in #34282 .
Misc:
Dependency Updates:
Upgraded tar from 6.2.1 to 7.5.21 to address CVE-2026-59873 reported in security scans. Addresses #34333 . Addressed in #34335 .
Upgraded arch from 2.2.0 to 3.0.0 . Addressed in #34426 .
Removed tslib (previously 1.14.1 ) from the cypress package's runtime dependencies. Addressed in #34372 .
Upgraded ws from 8.18.3 to 8.21.1 . Addressed in #34392 .
Changelog: https://docs.cypress.io/app/references/changelog#15-19-0
Released Jul 21, 2026
Performance:
Fixed an issue where the browser's renderer process could crash ( We detected that the Chrome Renderer process just crashed ) when the application under test triggered a ResizeObserver loop while the command log was visible. Fixes #33962 and #34218 .
Fixed a regression in 14.0.0 where each message sent from the Cypress server to a Chromium-based browser (including Electron) leaked a small amount of browser memory until the end of the spec. During long, command- or network-heavy specs, this buildup could crash the browser ( We detected that the Chrome Renderer process just crashed ). Fixes #34226 .
Fixed an issue where each cy.press() call in Chromium-based browsers retained a small amount of renderer memory for the remainder of the spec file, which could contribute to memory growth in specs with many cy.press() calls. Addressed in #34240 .
Features:
Added support for TypeScript 7 when preprocessing TypeScript spec and support files. The component testing setup wizard now accepts TypeScript 7 as well. Addresses #34258 . Addressed in #34277 .
Added support for additional assertion aliases: .exists (alias of .exist ), .greaterThanOrEqual and .lessThanOrEqual (aliases of .least and .most ), and .oneOf chained with .contain (for example expect('Today is sunny').to.contain.oneOf(['sunny', 'cloudy']) ). These can be used anywhere Cypress assertions are written, such as expect , assert , and cy.get(...).should(...) . This comes from upgrading the bundled chai assertion library from 4.2.0 to 4.5.0 ; all existing assertions and their messages behave the same. Addressed in #34178 .
Bugfixes:
Fixed an issue where chaining an assertion after .should('exist') on a raw DOM element (rather than a jQuery object) failed with expected null to exist , because the existence assertion replaced the subject with null . Chaining further assertions off .exist (or its .exists alias) for a raw DOM element now works as expected. Fixes #25491 .
Fixed an issue where, on Windows, enhancing a test failure stack could throw a secondary TypeError: Cannot read properties of undefined (reading 'replaceAll') and mask the original error. Fixed in #34252 .
Fixed an issue where experimentalMemoryManagement could fail to prevent the browser from running out of memory and crashing when Cypress was running inside a memory-limited container. Memory is now managed correctly in these environments. Fixes #34104 . Addressed in #34123 .
Misc:
Changelog: https://docs.cypress.io/app/references/changelog#15-18-1
Released Jul 7, 2026
Performance:
Bugfixes:
Fixed an issue where Cypress could hang until the spec timed out if the browser process crashed mid-run (for example, an out-of-memory or GPU crash) while video recording was disabled. The current spec now fails and the run continues to the next spec as expected. Fixed in #34126 .
Fixed an issue where asserting focus with Chai's property syntax, such as expect($el).to.have.focus or expect($el).to.be.focused , raised a TypeScript error ( Property 'focus' does not exist on type 'Assertion' ) even though the assertion works at runtime. Fixes #23905 . Fixed in #34177 .
Fixed an issue where cy.type() fired the simulated keyup event in the same turn as keydown and input , so keyup handlers that read state updated asynchronously in an input listener could observe stale values. keyup is now deferred to the next microtask, matching real browser event ordering. Fixes #14864 . Fixed in #34068 .
Fixed an issue where headless WebKit used the host machine's devicePixelRatio instead of a standard value of 1 . Headless WebKit now matches headless Chrome, so screenshots taken during cypress run are consistent regardless of the host's DPI (for example 2x locally versus 1x in CI) and text is no longer fuzzy on high-DPI displays. Applies when experimentalWebKitSupport is enabled. Fixes #23808 . Fixed in #34088 .
Fixed an issue where the userAgent configuration option was not applied when running tests in the experimental WebKit browser. Fixes #33349 .
Fixed an issue where, in the experimental WebKit browser, a request to focus the browser window was silently ignored, so the window could remain in the background. The active page is now correctly brought to the front. Addressed in #34137 .
Fixed an issue where opening an unconfigured project from a git repository sub-directory (such as a monorepo package) skipped project setup. Additionally, the component testing setup wizard now reliably displays the auto-detected framework and bundler. Fixes #27410 and #29544 . Fixed in #34129 and #34212 .
Fixed an issue where interacting with an element inside a horizontally-scrollable container could scroll the element to the container's right edge, placing it underneath a right-floating position: sticky or position: fixed element and causing the action to fail or land on the wrong element. Elements are now scrolled to their top, leftmost point as documented. Fixes #33884 . Fixed in #34108 .
Fixed a regression in 15.17.0 where cypress run --spec printed a spurious The following --spec pattern did not match any spec files and will be ignored warning for patterns that actually did match spec files, such as patterns using regex-style alternation groups (for example cypress/e2e/(a|b)/*.js ). Fixes #34160 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-18-0
Changelog: https://docs.cypress.io/app/references/changelog#15-18-0
Released Jun 23, 2026
Performance:
Features:
Bugfixes:
Fixed an issue where calling req.destroy() or using { forceNetworkError: true } inside a cy.intercept() handler in experimental WebKit caused infinite request loops. Fixes #23810 . Fixed in #33948 .
Fixed an issue where the before:spec plugin event fired twice for the same spec when a test navigated to a cross-origin URL via cy.visit() . Affects cypress run and cypress open with experimentalInteractiveRunEvents enabled. The event now fires exactly once per spec run, regardless of how many times the runner page reloads internally during cross-origin navigation. Fixes #26300 .
Fixed an issue where setting numTestsKeptInMemory to a value greater than 0 from setupNodeEvents would take effect during cypress run , which could prevent snapshots from being captured correctly when recording Test Replay to Cypress Cloud. During cypress run , numTestsKeptInMemory is now always treated as 0 regardless of how it is configured. Fixes #31167 .
Fixed an issue where, when Cypress was installed in a read-only location, running tests in Firefox or Chrome could log a cannot delete profileDir on exit error ( EACCES / EPERM ) and leave the browser profile directory behind, requiring manual cleanup before the next run. Cypress now removes the profile directory on exit as expected. Fixes #31300 .
Fixed an issue where the resolved remote origin (for example, Cypress.config('remote').origin ) could include an explicit default port ( :80 for HTTP or :443 for HTTPS) or embedded credentials when the visited URL contained them, which did not match the origin reported by the browser. The reported origin now always matches the browser's location.origin , omitting default ports and any embedded credentials. Fixes #28369 . Fixed in #34050 .
Fixed an issue where cy.screenshot() could still capture changing pixels from some running web animations. Fixes #29144 .
Fixed an issue where, during cypress run with experimentalSingleTabRunMode and the experimental WebKit browser, component test runs with video recording enabled would only record the first spec's video and could then hang without exiting. Each spec is now recorded to its own video and the run exits normally. Fixes #23815 .
Fixed an issue where running component tests with the experimentalSingleTabRunMode experiment enabled could cause a spec to fail intermittently after many other specs had run in the same browser tab, even though that spec passed when run on its own. Fixes #24146 .
Fixed an issue where passing a cy.fixture() alias to cy.selectFile() attached the file without its name in a second or later test that loaded the same fixture (for example, when the same fixture is reused across multiple tests), causing servers to reject the upload as a missing file. The file name is now preserved every time the fixture is used. Fixes #21936 .
Fixed a regression in 15.17.0 where loading the Cypress configuration could fail with TransformError: Internal error: Expected id N but got id M when the project has the same esbuild version installed that Cypress bundles internally (currently 0.28.0 ) and a dependency loaded during config processing registers its own tsx loader. The tsx loader Cypress uses to load the configuration file is now removed from NODE_OPTIONS before the configuration file is sourced, so it no longer executes inside worker threads spawned by the project's own dependencies. Fixes #34076 .
Fixed an issue where cy.request() in Firefox did not send Secure cookies to localhost or loopback addresses such as 127.0.0.1 over http , even though browsers treat those origins as secure contexts. A Secure cookie set over https on such a host is now included on subsequent http requests to that host in Firefox, matching the browser's own behavior and how Cypress already behaves in Chrome. Fixes #24332 .
Fixed an issue where a transient failure to bind Cypress's internal file server to an available port (for example, an intermittent EADDRINUSE under port pressure on a reused CI machine) could crash the run with an uncaught exception before any tests started. Cypress now retries on a fresh port and, if it still cannot bind, fails with a clear error instead of crashing. Fixes #34109 .
Fixed a regression in 15.17.0 where visiting a URL with an IPv6 literal host, such as cy.visit('http://[::1]:3000') , crashed the proxy with an Internal error while proxying ... option domain is invalid error. Cypress no longer sets a Domain attribute on its internal cookies for IPv6 hosts, so such URLs work as expected. Fixes #34143 . Fixed in #34146 .
Misc:
Running cypress install when Cypress is installed globally no longer prints a warning recommending that Cypress be installed as a per-project devDependency. Addresses #34134 .
Running Cypress with process profiler debug logs enabled (for example DEBUG=cypress*process_profiler ) no longer intermittently prints an Expected DataContext to already have been set via setCtx error to the logs. Addresses #30670 .
Cypress now shows a clear error explaining that browsers must be an array and that a specific browser should be selected with --browser when a CYPRESS_BROWSERS environment variable is set to a plain string (for example CYPRESS_BROWSERS=chrome ) instead of showing an opaque TypeError: a.map is not a function error. Addresses #33198 .
Dependency Updates:
Upgraded webdriver from 9.14.0 to 9.28.0 , geckodriver from 5.0.0 to 6.1.0 , and edgedriver from 6.1.1 to 6.3.0 . These packages are used to launch and automate Firefox during cypress run and cypress open . Addresses #34072 .
Upgraded undici from 6.26.0 to 6.27.0 to address a CRLF Injection vulnerability reported in security scans. Addressed in #34121 .
Changelog: https://docs.cypress.io/app/references/changelog#15-17-0
Changelog: https://docs.cypress.io/app/references/changelog#15-17-0
Released Jun 9, 2026
Performance:
The Command Log no longer becomes progressively unresponsive when moving the mouse in and out of a test's command list during long tests. Hovering over the command area previously triggered a style recalculation across the entire list of commands, causing a delay that grew with the number of commands logged. Fixes #33179 .
Fixed a memory leak where runs with screenshotOnRunFailure enabled slowed down progressively, as each failure screenshot was retained in memory for the rest of the run. Fixes #33516 .
Features:
Added Bun as a recognized package manager. The cypress npm package can now be installed and invoked with Bun (for example bun run cypress open or bun run cypress run ). Addresses #28962 . Addressed in #32580 .
Cypress.expose() values can now be overridden per suite or test via test config overrides (for example, describe() , context() , it() , or test() ) using { expose: { key: value } } . Suite- and test-level overrides are merged, with test-level keys taking precedence; override keys are applied at test start and restored after each test without affecting unrelated values set in hooks. Addresses #33356 . Addressed in #33925 .
When signing up to Cypress Cloud from the Cypress desktop app, if a project is auto-provisioned during signup, Cypress now automatically writes the projectId to the cypress.config file. If the file cannot be written, a modal is shown with the project ID as a copyable snippet and a link to open the config file directly in your IDE. Addressed in #33976 .
Improved CI environment detection and commit metadata capture for Cypress Cloud recorded runs within Argo CD and Argo Workflows. Addressed in #33932 .
Bugfixes:
Video recording no longer silently fails on Firefox 93+, where it previously produced no video and ended with a We failed processing this video or operation timed out warning. Fixes #18415 . Fixed in #33960 .
Fixed an issue where, in the Electron browser, navigating away from a page whose beforeunload handler requested a confirmation prompt (for example window.onbeforeunload = () => 'message' or a beforeunload listener that sets event.returnValue ) would hang and eventually fail the command with a page load timeout. Such navigations — including cy.visit() , cy.reload() , and clicking links — now proceed automatically without the confirmation prompt blocking the test, matching the behavior in Chrome. Fixes #2118 .
Fixed an issue where config.isInteractive was always true in the config passed to the plugins / setupNodeEvents function, even during cypress run . The value is now correctly false in run mode and true in open mode, so plugins can reliably distinguish between the two. Fixes #20789 .
Fixed an issue where component tests, and end-to-end tests using a local baseUrl , could fail to start with Cypress could not verify that this server is running when an HTTP_PROXY environment variable was set. Local hosts excluded from the proxy via NO_PROXY (such as localhost , 127.0.0.1 , and ::1 , which includes the component testing dev server) are now verified with a direct connection instead of being routed through the proxy. Fixes #27990 .
Fixed an issue where cy.wait('@alias') could time out when the connection to the browser closed before an aliased intercepted request's response completed, including during navigation such as cy.visit() . Fixes #19326 .
Fixed an issue where cy.request() with a FormData body failed to upload when a Content-Type header was provided with non-lowercase casing (for example 'Content-Type': 'multipart/form-data' ). Cypress now correctly replaces the user-provided header with the generated multipart/form-data boundary instead of sending two conflicting content-type headers, which previously caused the server to reject the request with a 400 or empty body. Fixes #21173 .
Fixed an issue where Cypress could load the config file through the wrong module system (for example, treating an ESM config as CommonJS), so ESM-only APIs such as import.meta.resolve were unavailable in config and plugin code. Cypress now picks ESM or CJS before loading, using Node.js rules from the config file extension and the nearest package.json "type" , then loads only via import() or require() and fails outright on error instead of retrying the other format:
.mjs and .mts always load as ESM
.cjs and .cts always load as CJS
.js and .ts load as ESM when the nearest package.json has "type": "module" ; CJS is loaded otherwise
Fixes #33801 . Addresses #33892 .
Fixed an issue where a recorded Chrome or Electron run could hang for the duration of the spec timeout when the renderer crashed mid-spec, instead of failing the affected spec and continuing. Fixed in #33943 .
Fixed an issue where tests in Chrome and Electron could fail when the application made cross-origin requests to local or private network addresses (for example, a login or OAuth flow that redirects between local development hosts). Chrome 141 began enforcing Local Network Access checks that gate such requests behind a permission prompt the automated browser cannot answer. Cypress now opts out of these checks so these requests succeed as they did in Chrome 140. Fixes #32708 .
Fixed an issue where, after a same-origin fetch or XHR request updated a cookie, a subsequent page navigation or reload could send the previous (stale) cookie value to the server instead of the updated one. Fixes #25841 .
Fixed an issue where a cross-origin navigation back to a previously-visited origin (for example, completing a login that redirects from an identity provider back to your application) could intermittently load the Cypress app interface instead of your application, causing flaky tests. Fixed in #33991 .
Fixed an issue where a cy.origin() test could intermittently fail with The command was expected to run against origin <x> but the application is at origin <y> when a navigation (such as a login redirect) ran on the primary origin shortly after the runner switched super-domains. A stale internal __cypress.unload cookie could cause the proxy to redirect the navigation back to the Cypress runner instead of serving it; the cookie is now cleared whenever the application document is (re)served. Fixed in #34020 .
Fixed an issue where setting a request or response header to an empty string in a cy.intercept() handler (for example req.headers['x-foo'] = '' ) would report the header as set on the intercepted request while silently dropping it from the request sent over the network. Empty-string header values are now preserved; headers are only removed when deleted or set to undefined . Fixes #25767 .
Fixed an issue where runs recorded to Cypress Cloud from Jenkins could show the branch name with the remote prefix included (for example origin/main instead of main ), or report the wrong branch in multibranch pipelines. Cypress now reports the actual branch name. Fixes #20833 .
Fixed an issue where invalid CYPRESS_env or CYPRESS_expose environment variables (for example, a plain string instead of a JSON object) were silently ignored with no warning. Cypress now emits a warning explaining that a JSON object is required and points to the --env or --expose CLI flags for setting individual values. Fixes #29682 and #19508 . Fixed in #33945 .
Fixed an issue where cypress run could crash with TypeError: The "path" argument must be of type string. Received undefined when the project path was not resolved (for example, due to an unset CI environment variable) or when --browser was passed without a value. Cypress now falls back to the current working directory in the first case and emits a clear "browser not found" error in the second. Fixes #15418 . Fixed in #33958 .
Fixed an issue where HTML markup passed as a Sinon spy argument (for example expect(spy).to.have.been.calledOnceWith('<svg>...</svg>') ) was rendered as live DOM in the Cypress command log, truncating the assertion message and breaking the log layout. The assertion message is now HTML-escaped and the markup is shown as literal text. Fixes #33416 . Fixed in #33941 .
Fixed a regression in 14.4.0 where Cypress incorrectly logged Warning: We failed to trash the existing run results. on Windows when the Recycle Bin is configured with "Don't move files to the Recycle Bin. Remove files immediately when deleted.", even though the assets were actually removed. Fixes #32691 .
Fixed an issue where a test or attempt that had not reached a terminal state (for example, after an interrupted or crashed run) could be reported to Cypress Cloud with an internal, display-only processing state that the Cloud rejects. Such in-flight states are now reported as pending . Fixes #27956 .
Fixed an issue where the version of WebKit was incorrectly displayed as version 0 when playwright version 1.60.0 was installed. Fixes #33953 .
Fixed an issue where clicking a cy.origin command in the Command Log to print its details to the console threw an error when the callback yielded a value that could not be serialized across origins (for example, the page's window after a cy.visit ). The command now prints its origin, arguments, and yielded subject to the console without erroring; an unserializable yielded subject is shown by its type instead of throwing. Fixes #27385 . Fixed in #33983 .
The internal --dev , --inspect , and --inspect-brk command line flags are no longer listed in the cypress CLI help output. These flags are only intended for developing Cypress itself and would error when used against an installed version, so they are no longer advertised to users. Fixes #21320 and addresses #23058 .
Fixed an issue where cypress open --detached blocked the CLI process until the GUI was closed rather than returning once Cypress was ready to use. Fixed in #33972 .
Misc:
Improved TypeScript types for cy.get('@alias') and cy.wait('@alias') so that @ -prefixed strings correctly resolve to Chainable<S> instead of Chainable<JQuery<HTMLElement>> . Addresses #8762 .
When running cypress run --spec with multiple patterns and one or more patterns do not match any spec files, Cypress now emits a warning identifying each unmatched pattern instead of silently skipping it. Addresses #22645 .
When Cypress cannot connect to a Chromium-based browser such as Chrome or Edge over the Chrome DevTools Protocol, the resulting error now suggests checking whether remote debugging has been disabled by an enterprise or group policy. Because Cypress relies on remote debugging to control the browser, the RemoteDebuggingAllowed policy being disabled prevents Cypress from connecting, and the error now points to chrome://policy or edge://policy to investigate. Addresses #32526 .
Dependency Updates:
Upgraded tsx from 4.20.6 to 4.22.4 . Its bundled esbuild Go binary no longer reports CVE-2025-68121 in security scans, and loading TypeScript config files no longer emits the Node.js [DEP0205] module.register() is deprecated warning. Fixes #33954 and #33744 .
Upgraded watchpack (a transitive dependency of webpack ) from 2.4.2 to 2.5.1 . On Windows, running a spec in cypress open from an elevated (Administrator) shell no longer logs Watchpack Error (initial scan): EINVAL warnings for root-of-drive system files such as pagefile.sys . Fixes #33586 .
Changelog: https://docs.cypress.io/app/references/changelog#15-16-0
Changelog: https://docs.cypress.io/app/references/changelog#15-16-0
Released May 26, 2026
Features:
Cypress Cloud sign up is supported from the Cypress desktop app in addition to log in. Addressed in #33805 .
The Cypress Cloud log in and sign up modals in the Cypress desktop app now automatically start the browser-based authentication flow when opened, removing the extra "Log in" click. Addressed in #33831 .
Bugfixes:
Fixed an issue on Node 24.16.0 + and Node 26.1.0 + where installing Cypress could silently extract only the first file from the binary archive, causing the test runner to fail to launch with a "Cypress binary is missing" error. Addresses #33891 . Addressed in #33887 .
Fixed a regression in 15.14.2 where the cypress install and cypress verify task list output could render one character per line in CI environments that allocate a pseudo-TTY without setting COLUMNS . Fixed in #33890 .
Fixed an issue where Cypress would abort the process and show a crash dialog when it received a SIGINT. Fixes #29228 . Fixed in #33542 .
Fixed an issue where the clientCertificates config option failed to load ECDSA (EC) PEM or PKCS#12 client certificates. Fixes #33767 . Fixed in #33799 .
Fixed an issue where clicking "back to projects" or switching projects while a project's initial config load was still in flight could fail. Fixed in #33810 .
Fixed an intermittent ENOENT: no such file or directory, open <path>/bundle.tar-<rand> error during cy.prompt and Studio bundle initialization. Fixed in #33748 .
Fixed a regression in 14.3.3 where deleting results.video in after:spec to keep videos only for failing specs could leave an empty *-compressed.mp4 file in cypress/videos . Fixes #32883 .
Fixed an issue where Cypress's bundled TypeScript type definitions could fail to compile in a project that also installed @sinonjs/fake-timers@>=15.3.0 , because the bundled @types/sinon file imported FakeTimers from @sinonjs/fake-timers and TypeScript would prefer the user's installed copy over the bundled @types/sinonjs__fake-timers . The shipped types now reference the @types package directly so resolution is independent of the user's installed version. Fixes #33829 . Fixed in #33886 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-15-0
Changelog: https://docs.cypress.io/app/references/changelog#15-15-0
Released May 12, 2026
Deprecations:
Bugfixes:
Fixed an issue where the proxy stripped Content-Length: 0 from empty responses (e.g. a DELETE 200 with no body) and the resulting empty body was re-emitted with Transfer-Encoding: chunked , breaking clients that assume a fixed-length response. Partially addresses #16469 . Fixed in #33754 .
Fixed an issue where component specs that defined local React components could register every describe / it block twice in cypress open when using Vite 8, because React refresh treated those specs as HMR self-accepting modules. @cypress/vite-dev-server now excludes component spec files from JSX refresh while leaving Fast Refresh enabled for application source. Fixes #33750 .
Fixed an issue where multi-origin tests using cy.origin could fail to talk to a secondary origin after test isolation, when the spec-bridge iframe was already present, or when more than one secondary origin became ready around the same time. Cached spec-bridge window targets are now cleared at the correct lifecycle points, improving performance of specs with cy.origin calls. Addressed in #33704 .
Fixed an issue where a CSS selector built internally from element attributes could throw an uncaught Syntax error, unrecognized expression and crash the runner when an attribute value contained CSS-special characters (for example, an <input> with a pattern attribute containing regex metacharacters). Fixes #26967 and #29345 .
Fixed an issue where transient HTTP 500 responses from Cypress Cloud were not retried for idempotent requests. Fixed in #33718 .
Fixed an issue in Angular component testing where multiple projects in a monorepo sharing the same directory basename (e.g. libs/feature-a/feat-shell and libs/feature-b/feat-shell ) would intermittently fail with spec-resolution errors when run in parallel. The temporary tsconfig.json generated by @cypress/webpack-dev-server was keyed only on the directory basename, so parallel runs would race on the same file. The temp directory is now suffixed with a short hash of the full project root path, giving each project its own isolated config. Fixes #33634 .
Fixed a race during cypress open config reload where rapid changes to cypress.config.js could leave the specs list stale. Two overlapping config-reload calls would tear down each other's IPC child processes (surfacing as ERR_STREAM_DESTROYED ), causing both reloads to fail and the specs list to never refresh. Fixed in #33775 .
Fixed an issue where a transient Firefox launch failure caused Cypress to exit instead of retrying the browser launch. Fixed in #33770 .
Dependency Updates:
Upgraded socket.io from 4.0.1 to 4.8.3 , socket.io-client from 4.0.1 to 4.8.3 , and socket.io-parser from 4.0.5 to 4.2.6 to address a Denial of Service vulnerability reported in security scans. The engine.io , engine.io-client , and engine.io-parser direct deps in @packages/socket were also bumped to keep transitive copies aligned and the existing browser-side patches applied. Addressed in #33719 .
Upgraded uuid from 8.3.2 to 11.1.1 to address an Improper Validation of Specified Index, Position, or Offset in Input vulnerability reported in security scans. Addressed in #33765 .
Changelog: https://docs.cypress.io/app/references/changelog#15-14-2
Changelog: https://docs.cypress.io/app/references/changelog#15-14-2
Released Apr 29, 2026
Performance:
Bugfixes:
Fixed an issue where cy.wait on multiple aliases could surface an unhandled Cannot read properties of undefined (reading 'routeId') rejection when a retry short-circuited during runnable teardown. Fixed in #33651 .
Fixed an issue where an application under test containing <base target="_top"> or <base target="_parent"> would navigate out of the Cypress iframe when untargeted links were clicked or forms were submitted, breaking the test run. The unsafe target is now stripped from <base> tags as part of the existing modifyObstructiveCode rewriting (enabled by default for the primary super-domain, and extendable to third-party origins with experimentalModifyObstructiveThirdPartyCode ). A runtime guard also neutralizes any <base> inserted or modified after load, matching the always-on behavior of the existing <a> / <form> target guards. Fixed in #33667 .
Fixed a race during cypress open config reload where the internal HTTP server would begin accepting requests before the primary remote state had been initialized, occasionally crashing in-flight browser requests (iframe loads) on an empty remoteStates map. Fixed in #33686 .
Dependency Updates:
Upgraded cachedir from ^2.3.0 to ^2.4.0 . Addressed in #33608 .
Upgraded listr2 from 3.8.3 to ^9.0.5 . Addressed in #33640 .
Upgraded simple-git from 3.33.0 to 3.36.0 to address a Remote Code Execution vulnerability reported in security scans. Addressed in #33680 .
Upgraded ts-loader from 9.5.2 to 9.5.7 . Addresses #33648 . Addressed in #33691 .
Changelog: https://docs.cypress.io/app/references/changelog#15-14-1
Changelog: https://docs.cypress.io/app/references/changelog#15-14-1
Released Apr 21, 2026
Performance:
Bugfixes:
Increased the limit for decrypted payloads to support large cy.prompt requests and responses. Fixed in #33619 .
Fixed a race condition in @cypress/vite-dev-server where the Cypress iframe could attempt to import the support file before Vite had finished serving it, causing intermittent "Failed to fetch dynamically imported module" errors in component tests. The dev server now waits until the support file URL returns a successful response before signaling that it is ready. Addressed in #33487 .
Fixed an issue where early-exit crashes (such as config errors or renderer crashes) left the in-flight test with a generic failure instead of the actual fatal error. The fatal error is now attached to the failing test attempt so Cypress Cloud displays the underlying cause. Addressed in #33617 .
Changelog: https://docs.cypress.io/app/references/changelog#15-14-0
Changelog: https://docs.cypress.io/app/references/changelog#15-14-0
Released Apr 16, 2026
Performance:
Features:
Cypress now officially supports TypeScript 6. Addresses #33385 and #33511 .
Adds Vite 8 support for component testing. Addresses #32550 and #33078 .
Bugfixes:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-13-1
Changelog: https://docs.cypress.io/app/references/changelog#15-13-1
Released Apr 07, 2026
Performance:
When recording to Cypress Cloud, the App now sends a smaller snapshot of your project config, which reduces payload size and can make Cloud recording faster. Addressed in #33517 .
Eliminated unnecessary git status and git log subprocess calls during cypress run , which were collecting spec file git metadata only used in the interactive GUI. Fixed in #33552 .
Bugfixes:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-13-0
Changelog: https://docs.cypress.io/app/references/changelog#15-13-0
Released Mar 24, 2026
Features:
cy.prompt is now in beta and available without any configuration. cy.prompt is an AI-powered command that lets you write test steps in plain English instead of code. The experimentalPromptCommand flag was removed and can be deleted from your config. Addressed in #33497 .
Studio now allows adding a new test when focused on a single test, supporting a workflow to add new tests as you record. Addressed in #33481 .
Bugfixes:
Misc:
When a test is isolated in Studio, the 'rerun' button now properly says 'Run test'. Addressed in #33466 .
Studio now warns users before navigating if they try to exit when they have unsaved changes in the editor. Addressed in #33457 .
Dependency Updates:
Upgraded simple-git from 3.27.0 to 3.32.3 to address Improper Handling of Case Sensitivity (CVE-2026-28292) vulnerability reported in security scans. Addressed in #33470 .
Upgraded minimatch to 3.1.3 to address CVE-2026-26996 , CVE-2026-27903 , and CVE-2026-27904 ReDoS vulnerabilities reported in security scans. Addressed in #33461 .
Upgraded serialize-javascript to 7.0.3 to address GHSA-5c6j-r48x-rmvq vulnerability reported in security scans. Addressed in #33461 .
Upgraded flatted from 3.2.9 to 3.4.2 to address Prototype Pollution (CVE-2026-33228) vulnerability reported in security scans. Addressed in #33501 .
Changelog: https://docs.cypress.io/app/references/changelog#15-12-0
Changelog: https://docs.cypress.io/app/references/changelog#15-12-0
Released Mar 13, 2026
Features:
Bugfixes:
Fixed an issue where sending SIGINT (e.g. Ctrl+C) to exit Cypress left the terminal displaying raw characters. Fixes #33367 . Addressed in #33431 .
Fixed an issue in develop mode (when running Cypress via gulp with file watching) where closing the Electron window did not exit the gulp process, leaving it running. Addressed in #33431 .
Fixed an issue where internal tags on stderr streams were surfacing to the end user CLI during component testing. Addresses #32769 . Addressed in #33400 .
Fixed an issue where Cypress may hang when waiting on multiple intercepts and the page navigates causing a stability change. Addressed in #33446 .
Dependency Updates:
Upgraded basic-ftp to 5.2.0 to address CVE-2026-27699 vulnerability reported in security scans. Addresses #33436 .
Upgraded fast-xml-parser to 4.5.4 to address CVE-2026-25896 vulnerability reported in security scans. Addresses #33434 .
Changelog: https://docs.cypress.io/app/references/changelog#15-11-0
Changelog: https://docs.cypress.io/app/references/changelog#15-11-0
Released Feb 25, 2026
Features:
Adds --pass-with-no-tests command line flag. Addresses #23019 . Addressed in #33384 .
Introduces manual bootstrap script injection via a <script data-cy-bootstrap> tag. This is a workaround to fix React SSR hydration mismatches, and enables React apps to use suppressHydrationWarning to ignore the mismatch. Addresses #27204 . Addressed in #33295 .
Added Brotli compression support to the proxy. Addresses #6197 .
Improved CI environment detection and CI/commit metadata capture for Cypress Cloud recorded runs. Added support for Harness CI, AWS Amplify Console, Buddy, Bitrise, and Cloudbees Unify and removed support for EOL providers. Addressed in #33396 .
Bugfixes:
Fixed an issue where a cancelled or incomplete login attempt would not properly open a browser window or tab, and required a restart of Cypress to enable a new login attempt. Fixed in #33366 . Fixes #33350 .
Fixed an issue on Windows where extracting the Studio or Prompt bundle could fail with EPERM: operation not permitted when renaming extracted files. The extract step now retries on EPERM/EACCES with a short delay to handle transient file locks. Addressed in #33330 .
The capture protocol is now properly cleaned up when the protocol is re-initialized or when the run closes, ensuring CDP client listeners and resources are removed. Addressed in #33391 .
Misc:
The Node.js path is now displayed correctly in run log headers for typical GitHub Actions paths. ANSI escape sequences are no longer incorrectly displayed for longer Node.js paths. Addresses #32736 .
Fixed an issue that caused a Node.js DEP0169 deprecation warning to be output when executing cypress install to download and install the Cypress binary. Addresses #33347 .
Dependency Updates:
Upgraded qs to 6.14.2 to address CVE-2026-2391 vulnerability reported in security scans. Addresses #33363 .
Upgraded rimraf to 6.1.1 to address CVE-2026-25547 vulnerability reported in security scans. Addressed in #33336 .
Upgraded squirrelly to 9.1.0 to address CVE-2021-32819 vulnerability reported in security scans. Addresses #33354 .
Upgraded systeminformation to 5.31.1 to address CVE-2026-26280 and CVE-2026-26318 vulnerabilities reported in security scans. Addresses #33389 .
Changelog: https://docs.cypress.io/app/references/changelog#15-10-0
Changelog: https://docs.cypress.io/app/references/changelog#15-10-0
Released Feb 03, 2026
Deprecations:
Cypress.env() is now deprecated and will be removed in a future major release of Cypress. To understand why, and how to migrate, read our Migration Guide . Addressed in #33181 .
Features:
Introduced a new cy.env() command that can be used to asynchronously and securely access Cypress environment variables. Addressed in #33181 .
Added a allowCypressEnv configuration option that disallows use of the deprecated Cypress.env() API. Addressed in #33181 .
Introduced the new Cypress.expose() API, intended for use of public configuration of non-sensitive values. Addressed in #33238 .
Displays the resolved expose values in the App's resolved configuration user interface. Addressed in #33322 .
Bugfixes:
Misc:
Dependency Updates:
Upgraded express to 4.22.0 and body-parser to 1.20.4 . This removes the CVE-2025-15284 vulnerability being reported in security scans. Addressed in #33305 .
Upgraded lodash to 4.17.23 . This removes the CVE-2025-13465 vulnerability being reported in security scans. Addresses #33269 .
Upgraded shell-env to 4.0.1 and @cypress/commit-info to 2.2.2 . This removes the GMS-2020-2 vulnerability being reported in security scans. Addressed in #33226 and #33263 .
Changelog: https://docs.cypress.io/app/references/changelog#15-9-0
Changelog: https://docs.cypress.io/app/references/changelog#15-9-0
Released Jan 13, 2026
Features:
Changelog: https://docs.cypress.io/app/references/changelog#15-8-2
Changelog: https://docs.cypress.io/app/references/changelog#15-8-2
Released Jan 06, 2026
Bugfixes:
Fixed an issue where the ffprobe path was not properly configured for video operations. The path is now set at module load time, ensuring it's available for all video operations. Upgraded @ffprobe-installer/ffprobe from 1.1.0 to 2.1.2 to support darwin-arm64 (Apple Silicon). Addressed in #33136 .
Fixed an issue where test:after:run and test:after:run:async events were not firing after both a before all and after all hook failed. Addressed in #33172 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-8-1
Changelog: https://docs.cypress.io/app/references/changelog#15-8-1
Released Dec 18, 2025
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-8-0
Changelog: https://docs.cypress.io/app/references/changelog#15-8-0
Released Dec 16, 2025
Performance:
Features:
Angular version 21 is now supported within component testing. Addressed in #33004 .
Adds zoneless support for Angular Component Testing through the angular-zoneless mount function. Addresses #31504 and #30070 .
After receiving feedback on its usefulness outside of Studio, the Selector Playground is now available for all users in open mode. When opened, the playground automatically enables interactive mode to help you build and test selectors directly in your application. Addresses #32672 . Addressed in #33073 .
Bugfixes:
Fixed an issue where a EPIPE error shows up after CTRL+C is done in terminal. Fixes #30659 . Addressed in #32873 .
Fixed an issue where the browser would freeze when Cypress intercepts a synchronous XHR request and a routeHandler is used. Fixes #32874 . Addressed in #32925 .
Fixed an issue where Next.js Component Testing would not load correctly without a TypeScript-based Next config in versions 16.0.3 and up. Fixes #32968 .
Fixed an issue where the error message for not.have.length was not correctly displaying the expected length in the Command Log. Addressed in #18927 .
Fixed an issue where removeAttribute() would not work for attributes other than target on anchor or form elements after clicking links with target="_top" or target="_parent" . Fixes #26206 . Addressed in #33051 .
Dependency Updates:
Removed extraneous dependencies that are no longer used. Addressed in #33098 .
Upgraded brace-expansion . This removes the CVE-2025-5889 vulnerability being reported in security scans. Addressed in #33112 .
Upgraded form-data . This removes the CVE-2025-7783 vulnerability being reported in security scans. Addressed in #33113 .
Changelog: https://docs.cypress.io/app/references/changelog#15-7-1
Changelog: https://docs.cypress.io/app/references/changelog#15-7-1
Released Dec 02, 2025
Performance:
Bugfixes:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-7-0
Changelog: https://docs.cypress.io/app/references/changelog#15-7-0
Released Nov 19, 2025
Performance:
Features:
Bugfixes:
Fixed an issue where cy.wrap() would cause infinite recursion and freeze the Cypress App when called with objects containing circular references. Fixes #24715 . Addressed in #32917 .
Fixed an issue where top changes on test retries could cause attempt numbers to show up more than one time in the reporter and cause attempts to be lost in Test Replay. Addressed in #32888 .
Fixed an issue where stack traces that are used to determine a test's invocation details are sometimes incorrect. Addressed in #32699 .
Fixed an issue where larger than expected config values were causing issues in certain cases when recording to the Cypress Cloud. Addressed in #32957 .
Misc:
The keyboard shortcuts modal now displays the keyboard shortcut for saving Studio changes - ⌘ + s for Mac or Ctrl + s for Windows/Linux. Addressed #32862 . Addressed in #32864 .
The Cursor logo now correctly displays in the External editor dropdown. Addresses #32062 . Addressed in #32911 .
Changelog: https://docs.cypress.io/app/references/changelog#15-6-0
Changelog: https://docs.cypress.io/app/references/changelog#15-6-0
Released Nov 04, 2025
Features:
Added a 'Self-healed' badge to the Command Log when cy.prompt() steps automatically recover after the element they need is not found in the cache. Addressed in #32802 .
cy.prompt() will now show a warning in the Get code modal when there are unsaved changes in Studio that will be lost if the user saves the generated code. Addressed in #32741 .
Bugfixes:
Fixed an issue where command snapshots were not correctly displayed in Studio. Addressed in #32808 .
Chrome's autofill popup is now disabled when filling address and credit card forms during test execution. We also added some other Chrome flags and preferences that are common when automating browsers. Fixes #25608 . Addressed in #32811 .
Fixed an issue where grouped command text jumps up and down when expanding and collapsing in the command log. Addressed in #32757 .
Fixed an issue with grouped console prop items having a hard to read blue color in the console log and duplicate : characters being displayed. Addressed in #32776 .
Added more context to the error message shown when cy.prompt() fails to download. Addressed in #32822 .
Fixed an issue where absolute file paths were not correctly determined from the source map when the source map root was updated. Fixes #32809 .
Misc:
Add top padding for command log labels. Addressed in #32774 .
The hitbox for expanding a grouped command has been widened. Addresses #32778 . Addressed in #32783 .
Have cursor on hover of the AUT URL to show as pointer. Addresses #32777 . Addressed in #32782 .
WebKit now prefers a cookie's fully qualified domain when requesting a cookie value via cy.getCookie() . If none are found, the cookie's apex domain will be used as a fallback. Addresses #29954 , #29973 and #30392 . Addressed in #32852 .
The 'Next' tooltip style was updated. Addressed in #32866 .
Make test name header sticky in studio mode and in the tests list. Addresses #32591 . Addressed in #32840 .
The cy.exec() type now reflects the correct yielded response type of exitCode . Addresses #32875 . Addressed in #32885 .
Dependency Updates:
Upgraded better-sqlite3 from 11.10.0 to 12.4.1 . Addressed in #32755 .
Upgraded recast from 0.20.4 to 0.23.11 . Addressed in #32742 .
Changelog: https://docs.cypress.io/app/references/changelog#15-5-0
Changelog: https://docs.cypress.io/app/references/changelog#15-5-0
Released Oct 17, 2025
Features:
Bugfixes:
An error is no longer thrown during command execution when the application under test overwrites the window.$ property with a non-function. Fixes #1502 . Fixed in #32682 .
When running cypress in Cypress development environments, or when ELECTRON_ENABLE_LOGGING is otherwise set to 1, certain messages written to stderr will no longer be bracketed with verbose tags. Addresses #32569 . Addressed in #32674 .
Improve performance of time between specs by not resetting the file_systems StorageType state when executing the CDP command Storage.clearDataForOrigin . Fixed in #32703 .
Misc:
Browser detection in Cypress now always prefers 64-bit browser installs to 32-bit browser installs. Addressed in #32656 .
Update code button styles and rename Get Code for Code on cy.prompt() . Addressed in #32745 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-4-0
Changelog: https://docs.cypress.io/app/references/changelog#15-4-0
Released Oct 07, 2025
Features:
Cypress Studio is now available by default. You no longer have to set the experimentalStudio flag. Addresses #30997 . Addressed in #32571 .
An option is now available to 'Hide HTTP Requests' in the Cypress Command Log. This can be found in the new dropdown menu at the top of the Command Log. Addresses #7362 . Addressed in #32658 .
Added the --posix-exit-codes flag for the run command. When this flag is passed, Cypress will exit with 1 if any tests fail, rather than the number of failed tests. Addresses #32605 and #24695 . Addressed in #32609 .
cy.prompt() is now a reserved Cypress command, currently gated behind a feature flag that requires an invite from Cypress. This means any custom commands named 'prompt' will no longer work. Stay tuned for updates on when this feature will become more widely available. Addresses #31826 .
Bugfixes:
Fixed a regression introduced in 15.0.0 where dbus connection error messages appear in Docker containers when launching Cypress. Fixes #32290 .
Fixed code frames in cy.origin() so that failed commands will show the correct line/column within the corresponding spec file. Addressed in #32597 .
Fixed Cypress Cloud requests so that they properly verify SSL certificates. Addressed in #32629 .
Misc:
Added a dropdown menu in the Command Log that includes actions like Open in IDE and Add New Test in Studio, along with test preferences such as Auto-Scroll and Hide HTTP Requests. Addresses #32556 and #32558 . Addressed in #32611 .
Updated the Studio test editing header to include a Back button. This change ensures the Specs button remains functional for expanding or collapsing the specs panel. Addresses #32556 and #32558 . Addressed in #32611 .
Fixed the Studio panel resizing when dragging. Addressed in #32584 .
The Next button now maintains consistent visibility during stepping sessions when using cy.pause , staying visible but disabled when no immediate next command is available, providing clear visual feedback to users about stepping state. Addresses #32476 . Addressed in #32536 .
Dependency Updates:
Upgraded electron from 36.8.1 to 37.6.0 . Addressed in #32607 .
Upgraded bundled Node.js version from 22.18.0 to 22.19.0 . Addressed in #32607 .
Upgraded bundled Chromium version from 136.0.7103.177 to 138.0.7204.251 . Addressed in #32607 .
Changelog: https://docs.cypress.io/app/references/changelog#15-3-0
Changelog: https://docs.cypress.io/app/references/changelog#15-3-0
Released Sep 23, 2025
Features:
Bugfixes:
In development mode, Electron stderr is piped directly to Cypress' stderr to make it clear why Electron failed to start, if it fails to start. Fixes #32358 . Addressed in #32468 .
Fixed an issue where ESM Cypress configurations were not being interpreted correctly. Fixes #32493 . Fixed in #32515 .
Misc:
Update the styles for command grouping 'line' so on expansion it is displayed correctly. Addressed in #32521 .
Test hook names now correctly display with a semi-bold font weight. Addresses #32477 . Addressed in #32491 .
Updated the Cypress Studio panel to not show bottom border. Addresses #32478 .
Dependency Updates:
Upgraded electron from 36.4.0 to 36.8.1 . Addressed in #32371 .
Upgraded bundled Node.js version from 22.15.1 to 22.18.0 . Addressed in #32371 .
Upgraded bundled Chromium version from 136.0.7103.149 to 136.0.7103.177 . Addressed in #32371 .
Changelog: https://docs.cypress.io/app/references/changelog#15-2-0
Changelog: https://docs.cypress.io/app/references/changelog#15-2-0
Released Sep 09, 2025
Features:
Bugfixes:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#15-1-0
Changelog: https://docs.cypress.io/app/references/changelog#15-1-0
Released Sep 02, 2025
Features:
Bugfixes:
Fixed an issue where OS distributions and releases were sometimes not properly populated for Module API results and Cloud recordings. Fixes #30533 . Addressed in #32283 .
Fixed an issue where Cypress would fail to run on GNOME if GTK 4 and GTK 2/3 were detected in the Electron process. Addresses #32361 .
Fixed an issue where the open Studio button would incorrectly show for component tests. Addressed in #32315 .
Fixed an issue where the TypeScript compiler wasn't being resolved correctly when @cypress/webpack-batteries-included-preprocessor was used as a standalone package. Fixes #32338 .
Fixed an issue where tsx was not being loaded correctly into the Cypress configuration process due to spaces being present in the path. Fixes #32398 .
Misc:
Dependency Updates:
Upgraded esbuild from 0.15.3 to 0.25.2 . Addressed in #32231 .
Upgraded image-size from 1.1.1 to 1.2.1 . Addressed in #32232 .
Upgraded tar from 6.1.5 to 6.2.1 . Addressed in #32229 .
Upgraded axios from 1.8.3 to 1.11.0 . Addresses #32347 .
Changelog: https://docs.cypress.io/app/references/changelog#15-0-0
Changelog: https://docs.cypress.io/app/references/changelog#15-0-0
Released Aug 20, 2025
Summary
This release prepares Cypress Studio for the next era of AI-assisted test creation. You can record interactions, add assertions by right-clicking, and now edit tests inline without leaving Cypress. Turn on experimentalStudio in your config to try it out and share your feedback . Read more about the foundation for what's next in our blog post .
Breaking Changes:
info
Refer to the v15 Migration Guide for help migrating your code.
Removed support for Node.js 18 and Node.js 23. Addresses #31302 .
Removed support for Linux distributions with glibc older than 2.31 . This support is in-line with Node.js' support for Linux in Node v20+. Addressed in #31912 .
Removed support for Chrome DevTools Protocol with the Firefox browser. Addresses #31189 .
Removed support of the deprecated 3 argument signature of cy.stub . Use cy.stub(object, name).callsFake(fn) instead. Addresses #31346 .
@cypress/webpack-preprocessor no longer supports webpack version 4. Addresses #31344 . If you still need to use webpack version 4, see our migration guide .
To better align with best practices, @cypress/webpack-batteries-included-preprocessor no longer includes certain browser built-ins that were automatically provided by Webpack 4. The removed built-ins are assert , constants , crypto , domain , events , http , https , punycode , querystring , string_decoder , sys , timers , tty , url , util , vm , and zlib . However, we know that certain built-ins are popular, given that many users have files that are shared between their Cypress tests and node context. Because of this, @cypress/webpack-batteries-included-preprocessor will ship with built-in support for buffer , path , process , os , and stream . If there is a built-in that isn't supported by default and you need to add support, refer to the Webpack resolve.fallback documentation and the @cypress/webpack-batteries-included-preprocessor README . Addresses #31039 .
The application under test's pagehide event in Chromium browsers will no longer trigger Cypress's window:unload event. Addressed in #31853 .
The Cypress.SelectorPlayground API has been renamed to Cypress.ElementSelector . This API was renamed to accommodate its use for defining selectorPriority in Cypress Studio and our future cy.prompt release . Additionally, the getSelector method and the onElement option of defaults were removed from this API. Addresses #31801 . Addressed in #31889 and #32098 .
The direct download option for installing Cypress is no longer supported. Users should install via a package manager. Addressed in #32249 .
Updated execa from 1.0.0 to 4.1.0 . This changes the code property returned by cy.exec() to exitCode . Addressed in #32238 .
Component Testing breaking changes:
Removed support for Angular 17. The minimum supported version is now 18.0.0 . Addresses #31303 .
@cypress/angular now requires a minimum of zone.js 0.14.0 . Addresses #31582 .
The Cypress configuration wizard for Component Testing supports TypeScript 5.0 or greater. Addresses #31187 .
@cypress/vite-dev-server is now an ESM only package. You will no longer be able to use this package from a CommonJS context. Addresses #28373 , #29557 and #31882 .
Removed support for Vite 4 inside @cypress/vite-dev-server . The minimum Vite version is 5 . Addresses #32038 .
@cypress/webpack-dev-server no longer supports webpack-dev-server version 4. Addresses #31605 . If you still need to use webpack-dev-server version 4, see our migration guide .
Features:
cy.url() , cy.hash() , cy.go() , cy.reload() , cy.title() , and cy.location() now use the automation client (CDP for Chromium browsers and WebDriver BiDi for Firefox) to return the appropriate values from the commands to the user instead of the window object. This is to avoid cross origin issues with cy.origin() so these commands can be invoked anywhere inside a Cypress test without having to worry about origin access issues. Experimental WebKit still will use the window object to retrieve these values. Also, cy.window() will always return the current window object, regardless of origin restrictions. Not every property from the window object will be accessible depending on the origin context. Addresses #31196 .
Selectors accepted in the selectorPriority of the SelectorPlayground (renamed to ElementSelector ) API have been expanded to accept name and attributes:* . Additionally, the default selector priority used by Cypress now includes name . Addresses #31801 and #6876 . Addressed in #31889 .
tsx is now used in all cases to run the Cypress config, replacing ts-node for TypeScript and Node.js for CommonJS/ESM. This should allow for more interoperability for users who are using any variant of ES Modules. Addresses #8090 , #15724 , #21805 , #22273 , #22747 , #23141 , #25958 , #25959 , #26606 , #27359 , #27450 , #28442 , #28696 , #29186 , #30318 , #30718 , #30907 , #30915 , #30925 , #30954 , and #31185 .
Component Testing features:
@cypress/vite-dev-server now supports vite version 7. Addresses #31882 .
Angular version 20 is now supported within component testing. As of now, cypress/angular still requires zone.js and @angular-devkit/build-angular . Addresses #31304 .
Bugfixes:
Fixed an issue where Create from Component feature might not be able to parse React components from project files. Fixed in #31457 .
Fixed an issue where isSecureContext would be false on localhost when testing with Cypress. Addresses #18217 .
Fixed an issue where Angular legacy Output() decorators were broken when making component instance field references safe. Fixes #32137 .
Fixed an issue where .fixture() would not return updated content after the underlying file was modified via .writeFile() . The fixture cache is now properly invalidated when the backing file is written to, ensuring updated content is returned in subsequent .fixture() calls. Fixes #4716 .
Fixed an issue where .fixture() calls with a specified encoding would sometimes still attempt to parse the file based on its extension. Files with an explicit encoding are now always treated as raw content. Fixes #32139 .
Fixed an issue where .fixture() calls with different encoding options would return inconsistent content based on execution order. Fixes #32138 .
Filters content written to stderr to prevent Electron from spamming with inconsequential errors/warnings. This stderr content can be viewed by enabling the cypress:internal-stderr debug namespace. Fixes #32070 .
Fixed an issue where Angular Component Testing was printing extraneous warnings to the console by default. By default, errors only will now print to the console. This can still be overridden by passing in a custom webpack config or setting the verbose option inside your angular.json . Addresses #26456 .
Fixed an issue where ts-loader was improperly being detected inside @cypress/webpack-preprocessor . Fixes #32265 .
Fixed an issue where .fixture() calls with null and undefined encoding options would incorrectly share cache entries, causing unexpected content to be returned. Cache keys now properly distinguish between these encoding values. Fixes #32274 .
Misc:
The Cypress Command log has a new design when viewing a list of tests. Addresses #31677 . Addressed in #31914 .
Migration helpers and related errors are no longer shown when upgrading from Cypress versions earlier than 10.0.0. To migrate from a pre-10.0.0 version, upgrade one major version at a time to receive the appropriate guidance. Addresses #31345 . Addressed in https://github.com/cypress-io/cypress/pull/31629/ .
Dependency Updates:
Upgraded electron from 33.2.1 to 36.4.0 . Addresses #31257 . Addressed in #31912 .
Upgraded bundled Node.js version from 20.18.1 to 22.15.1 . Addresses #31257 . Addressed in #31912 .
Upgraded bundled Chromium version from 130.0.6723.137 to 136.0.7103.149 . Addresses #31257 . Addressed in #31912 .
Upgraded body-parser from 1.20.2 to 1.20.3 . This removes the SNYK-JS-BODYPARSER-7926860 vulnerability being reported in security scans. Addressed in #32225 .
Upgraded systeminformation from 5.22.8 to 5.27.7 . Addressed in #32234 .
Upgraded tmp from ~0.2.3 to ~0.2.4 . This removes the CVE-2025-54798 vulnerability being reported in security scans. Addresses #32176 .
Changelog: https://docs.cypress.io/app/references/changelog#14-5-4
Changelog: https://docs.cypress.io/app/references/changelog#14-5-4
Released Aug 07, 2025
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#14-5-3
Changelog: https://docs.cypress.io/app/references/changelog#14-5-3
Released Jul 25, 2025
Bugfixes:
Fixed missing support for setting an absolute path for component.indexHtmlFile in @cypress/webpack-dev-server . Fixes #31819 .
Fixed an issue where TypeScript ESM projects using .js and .mjs extensions were not resolving correctly within @cypress/webpack-batteries-included-preprocessor . Addressed in #31994 . Fixes #26827 and #28805 .
Fixed an issue in @cypress/angular where component instance fields were not reference safe and were being overwritten. Fixes #31238 and #31983 . Fixed in #31993 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#14-5-2
Changelog: https://docs.cypress.io/app/references/changelog#14-5-2
Released Jul 15, 2025
Bugfixes:
Fixed a regression introduced in 14.5.0 where the Stop button would not immediately stop the spec timer. Addresses #31920 .
Fixed an issue with the CloudRequest where it used the wrong port for https requests. Addressed in #31992 .
Changelog: https://docs.cypress.io/app/references/changelog#14-5-1
Changelog: https://docs.cypress.io/app/references/changelog#14-5-1
Released Jul 01, 2025
Bugfixes:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#14-5-0
Changelog: https://docs.cypress.io/app/references/changelog#14-5-0
Released Jun 17, 2025
Features:
Bugfixes:
Changelog: https://docs.cypress.io/app/references/changelog#14-4-1
Changelog: https://docs.cypress.io/app/references/changelog#14-4-1
Released Jun 03, 2025
Bugfixes:
Misc:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#14-4-0
Changelog: https://docs.cypress.io/app/references/changelog#14-4-0
Released May 20, 2025
Features:
Bugfixes:
Fixed an issue where framebusting was occurring when top.window.location was being set explicitly. This fix does not require the experimentalModifyObstructiveThirdPartyCode configuration option. Addresses #31687 .
cy.press() now has a return type of Chainable<null> instead of void to match the convention of other commands that yield null . Addressed in #31698 .
Fixed an issue with the experimental usage of WebKit where Cypress incorrectly displayed 0 as the WebKit version. Addresses #31684 .
Misc:
Chrome 137+ no longer supports --load-extension in branded Chrome, breaking the @cypress/puppeteer plugin in open mode and headed run mode and launchOptions.extensions . We recommend using Electron, Chrome for Testing or Chromium to continue using these features. See Cypress Docker image examples for Chrome for Testing and Chromium . Addresses #31702 and #31703 .
Cursor is now available as an IDE option for opening files in Cypress, if it is installed on your system. Addressed in #31691 .
The error shown when the --record flag is missing has been updated to be shorter. Addressed in #31676 .
Dependency Updates:
Upgraded @sinonjs/fake-timers from 8.1.0 to 10.3.0 . Addressed in #31725 and #31737 .
Upgraded trash from 5.2.0 to 7.2.0 . Addressed in #31667 .
Upgraded webdriver from 9.11.0 to 9.14.0 . Addressed in #31689 .
Changelog: https://docs.cypress.io/app/references/changelog#14-3-3
Changelog: https://docs.cypress.io/app/references/changelog#14-3-3
Released May 06, 2025
Performance:
Bugfixes:
Fixed an issue where the configuration setting trashAssetsBeforeRuns=false was ignored for assets in the videosFolder . These assets were incorrectly deleted before running tests with cypress run . Addresses #8280 .
Fixed a potential hang condition when @cypress/grep would match many files and stdout / stderr was piped to a file. Fixes #31625 . Addressed in #31631 .
Fixed a potential hang condition when navigating to about:blank . Addressed in #31634 .
Misc:
The Assertions menu when you right click in experimentalStudio tests now displays in dark mode. Addresses #10621 . Addressed in #31598 .
The URL in the Cypress App no longer displays a white background when the URL is loading. Fixes #31556 .
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#14-3-2
Changelog: https://docs.cypress.io/app/references/changelog#14-3-2
Released Apr 22, 2025
Bugfixes:
Fixed an issue where auto scroll in the Cypress Command Log was not scrolling correctly. Fixes #31530 .
Fixed an issue where a message pointing users to the Cypress Cloud was not displaying on runs with failures in CI. Fixes #31550 .
Changelog: https://docs.cypress.io/app/references/changelog#14-3-1
Changelog: https://docs.cypress.io/app/references/changelog#14-3-1
Released Apr 17, 2025
Performance:
Bugfixes:
The cy.press() command no longer errors when used in specs subsequent to the first spec in run mode. Fixes #31466 .
Fixed an issue where certain proxy conditions prevented test runs from being recorded. Fixes #31485 .
Misc:
Suppress benign warnings that reference OOM score of renderer. Addresses #29563 . Addressed in #31521 .
The UI of the reporter and URL were updated to a darker gray background for better color contrast. Addressed in #31475 .
Fixed an issue where the error message output when attempting to install Cypress on an unsupported architecture included an outdated documentation link to Cypress system requirements. Fixes #31512 .
Changelog: https://docs.cypress.io/app/references/changelog#14-3-0
Changelog: https://docs.cypress.io/app/references/changelog#14-3-0
Released Apr 08, 2025
Features:
Bugfixes:
Allows for babel-loader version 10 to be a peer dependency of @cypress/webpack-preprocessor . Fixed in #31218 .
Fixed an issue where Firefox BiDi was prematurely removing prerequests on pending requests. Fixes #31376 .
Fixed an issue with Electron causing slow animations and increased test times by starting a CDP screencast with a noop configuration. Fixes #30980 .
Misc:
Added an automation command for dispatching key press events to CDP and BiDi automated browsers. Addressed in #31366 .
Updated error message around injectDocumentDomain removal to mention a future version of Cypress instead of Cypress 15. Addresses #31373 . Addressed in #31375 .
Dependency Updates:
Upgraded mocha from 7.0.1 to 7.2.0 . Addressed in #31423 and #31432 .
Upgraded webdriver from 9.7.3 to 9.11.0 . Addressed in #31315 .
Upgraded win-version-info from 5.0.1 to 6.0.1 . Addressed in #31358 .
Changelog: https://docs.cypress.io/app/references/changelog#14-2-1
Changelog: https://docs.cypress.io/app/references/changelog#14-2-1
Released Mar 26, 2025
Bugfixes:
Applies a fix from #30730 and #30099 related to Node.js turning on ESM flags by default in Node.js version 20.19.0 . Fixed in #31308 .
Fixed an issue where Firefox BiDi was not correctly removing prerequests on expected network request failures. Fixes #31325 .
Fixed an issue in @cypress/webpack-batteries-included-preprocessor and @cypress/webpack-preprocessor where sourceMaps were not being set correctly in TypeScript 5. This should now make error code frames accurate for TypeScript 5 users. Fixes #29614 .
Misc:
Dependency Updates:
Upgraded @cypress/request from 3.0.7 to 3.0.8 . Addressed in #31311 .
Upgraded cross-fetch from 3.1.8 to 4.1.0 . Addressed in #31327 .
Upgraded micromatch from 4.0.6 to 4.0.8 . Addressed in #31330 .
Upgraded resolve from 1.17.0 to 1.22.10 . Addressed in #31333 .
Upgraded semver from 7.5.3 to 7.7.1 . Addressed in #31341 .
Upgraded systeminformation from 5.21.7 to 5.22.8 . Addressed in #31281 .
Changelog: https://docs.cypress.io/app/references/changelog#14-2-0
Changelog: https://docs.cypress.io/app/references/changelog#14-2-0
Released Mar 12, 2025
Features:
Misc:
The browser dropdown now has a more minimal design - showing only the icon of the browser selected to the left of the URL. The currently selected browser also now shows at the top of the browser dropdown. Browsers with longer names will now have their names correctly left aligned in the browser dropdown. Addresses #21755 and #30998 . Addressed in #31216 .
Additional CLI options will be displayed in the terminal for some Cloud error messages. Addressed in #31211 .
Updated Cypress Studio with url routing to support maintaining state when reloading. Addresses #31000 and #30996 .
Dependency Updates:
Upgraded cli-table3 from 0.5.1 to 0.6.5 . Addressed in #31166 .
Upgraded simple-git from 3.25.0 to 3.27.0 . Addressed in #31198 .
Changelog: https://docs.cypress.io/app/references/changelog#14-1-0
Changelog: https://docs.cypress.io/app/references/changelog#14-1-0
Released Feb 25, 2025
Features:
Bugfixes:
Misc:
Viewport width, height, and scale now display in a badge above the application under test. The dropdown describing how to set viewport height and width has been removed from the UI. Additionally, component tests now show a notice about URL navigation being disabled in component tests. Addresses #30999 . Addressed in #31119 .
Updated types around .readFile() and .scrollTo() arguments and Cypress.dom methods. Addressed in #31055 .
Updated types around .shadow() and .root() options. Addressed in #31154 .
Dependency Updates:
Upgraded chrome-remote-interface from 0.33.2 to 0.33.3 . Addressed in #31128 .
Upgraded ci-info from 4.0.0 to 4.1.0 . Addressed in #31132 .
Upgraded compression from 1.7.5 to 1.8.0 . Addressed in #31151 .
Changelog: https://docs.cypress.io/app/references/changelog#14-0-3
Changelog: https://docs.cypress.io/app/references/changelog#14-0-3
Released Feb 11, 2025
Bugfixes:
Dependency Updates:
Upgraded @cypress/request from 3.0.6 to 3.0.7 . Addressed in #31063 .
Upgraded compression from 1.7.4 to 1.7.5 . Addressed in #31004 .
Changelog: https://docs.cypress.io/app/references/changelog#14-0-2
Changelog: https://docs.cypress.io/app/references/changelog#14-0-2
Released Feb 05, 2025
Bugfixes:
Fixed a regression introduced in 14.0.0 where error codeframes in the runner UI were not populated with the correct data in failed retry attempts. Fixes #30927 .
All commands performed in after and afterEach hooks will now correctly retry when a test fails. Commands that are actions like .click() and .type() will now perform the action in this situation also. Fixes #2831 .
Fixed an issue in Cypress 14.0.0 where privileged commands did not run correctly when a spec file or support file contained characters that required encoding. Fixes #30933 .
Re-enabled retrying Cloud instance creation for runs that are parallel or recorded. Fixes #31002 .
Misc:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#14-0-1
Changelog: https://docs.cypress.io/app/references/changelog#14-0-1
Released Jan 28, 2025
Bugfixes:
Fixed an issue where Cypress would incorrectly navigate to about:blank when test isolation was disabled and the last test would fail and then retry. Fixes #28527 .
Fixed a regression introduced in 14.0.0 where an element would not return the correct visibility if its offset parent was within the clipping element. Fixes #30922 .
Fixed a regression introduced in 14.0.0 where the incorrect visibility would be returned when either overflow-x or overflow-y was visible but the other one was clipping. Fixed in #30934 .
Fixed an issue where an option element would not return the correct visibility if its parent element has a clipping overflow. Fixed in #30934 .
Fixed an issue where non-HTMLElement(s) may fail during assertions. Fixes #30944 .
Misc:
Corrected the broken documentation links displayed in Cypress 14.0.0 . Addresses #30951 . Addressed in #30953 .
Benign Mesa/GLX related warnings are now hidden in the terminal output when running Cypress in certain Linux environments or containers. Addresses #29521 and #29554 .
Changelog: https://docs.cypress.io/app/references/changelog#14-0-0
Changelog: https://docs.cypress.io/app/references/changelog#14-0-0
Released Jan 16, 2025
Summary:
Cypress 14.0.0 improves performance of component testing and adds support for new framework and dev server versions. 14.0.0 also includes breaking changes to cy.origin that are necessary to handle Chrome's deprecation of document.domain injection , which should fix issues for some users in recent Chrome versions. Support for older versions of Node.js, Linux distributions, browsers and component testing frameworks and dev servers is removed.
Overall, we don't anticipate this release to be too disruptive for most users. We recommend bumping your version to see if your tests still run as expected. As always, open a bug report for any issues you find.
Breaking Changes:
info
Refer to the v14 Migration Guide for help migrating your code.
Removed support for Node.js 16 and Node.js 21. Addresses #29930 .
Upgraded bundled Node.js version from 18.17.0 to 20.18.1 . Addresses #29547 .
Prebuilt binaries for Linux are no longer compatible with Linux distributions based on glibc <2.28 , for example: Ubuntu 14-18, RHEL 7, CentOS 7, Amazon Linux 2. Addresses #29601 .
Cypress now only officially supports the latest 3 major versions of Chrome, Firefox, and Edge - older browser versions may still work, but we recommend keeping your browsers up to date to ensure compatibility with Cypress. A warning will no longer be displayed on browser selection in the Launchpad for any 'unsupported' browser versions. Additionally, the undocumented minSupportedVersion property has been removed from Cypress.browser . Addressed in #30462 .
The cy.origin() command must now be used when navigating between subdomains. Because this is a fairly disruptive change for users who frequently navigate between subdomains, a new configuration option is being introduced. injectDocumentDomain can be set to true to re-enable the injection of document.domain setters in Cypress. This configuration option is marked as deprecated and you'll receive a warning when Cypress is launched with this option set to true . It will be removed in a future version of Cypress. Addressed in #30770 .
The experimentalSkipDomainInjection configuration has been removed and replaced with an injectDocumentDomain configuration. Addressed in #30770 .
It is no longer possible to make a fetch or XMLHttpRequest request from the about:blank page in Electron (i.e. cy.window().then((win) => win.fetch('<some-url>')) ). You must use cy.request instead or perform some form of initial navigation via cy.visit() . Addressed in #30394 .
The experimentalJustInTimeCompile configuration option for component testing has been replaced with a justInTimeCompile option that is true by default. This option will only compile resources directly related to your spec, compiling them 'just-in-time' before spec execution. This should result in improved memory management and performance for component tests in cypress open and cypress run modes, in particular for large component testing suites. justInTimeCompile is now only supported for webpack . Addresses #30234 . Addressed in #30641 .
Cypress Component Testing no longer supports:
create-react-app . Addresses #30028 .
@vue/cli-service . Addresses #30481 .
Angular versions 13, 14, 15, and 16. The minimum supported version is now 17.2.0 to fully support Angular signals . Addresses #29582 . Addressed in #30539 .
Next.js versions 10, 11, 12, and 13. Addresses #29583 .
Nuxt.js version 2. Addresses #30468 .
React versions 16 and 17. Addresses #29607 .
Svelte versions 3 and 4. Addresses #30492 and #30692 .
Vue version 2. Addresses #30295 .
The cypress/react18 test harness is no longer included in the Cypress binary. Instead, React 18 support is now shipped with cypress/react ! Addresses #29607 .
The cypress/angular-signals test harness is no longer included in the Cypress binary. Instead, signals support is now shipped with cypress/angular ! This requires rxjs to be installed as a peerDependency . Addresses #29606 .
The Cypress configuration wizard for Component Testing supports TypeScript 4.0 or greater. Addresses #30493 .
@cypress/webpack-dev-server no longer supports webpack-dev-server version 3. Additionally, @cypress/webpack-dev-server now ships with webpack-dev-server version 5 by default. webpack-dev-server version 4 will need to be installed alongside Cypress if you are still using webpack version 4. Addresses #29308 , #30347 , and #30141 .
@cypress/vite-dev-server no longer supports vite versions 2 and 3. Addresses #29377 and #29378 .
The delayMs option of cy.intercept() has been removed. This option was deprecated in Cypress 6.4.0 . Use the delay option instead. Addressed in #30463 .
The experimentalFetchPolyfill configuration option was removed. This option was deprecated in Cypress 6.0.0 . We recommend using cy.intercept() for handling fetch requests. Addressed in #30466 .
We removed yielding the second argument of before:browser:launch as an array of browser arguments. This behavior has been deprecated since Cypress 4.0.0 . Addressed in #30460 .
The cypress open-ct and cypress run-ct CLI commands were removed. Use cypress open --component or cypress run --component respectively instead. Addressed in #30456 .
The undocumented methods Cypress.backend('firefox:force:gc') and Cypress.backend('log:memory:pressure') were removed. Addresses #30222 .
Deprecations:
The resourceType option on cy.intercept has been deprecated. We anticipate the resource types to change or be completely removed in the future. Our intention is to replace essential functionality dependent on the resourceType within Cypress in a future version (like hiding network logs that are not fetch/xhr). Leave feedback on any essential uses of resourceType in this GitHub issue . Addresses #30433 .
The new injectDocumentDomain configuration option is released as deprecated. It will be removed in a future version of Cypress. Addressed in #30770 .
Features:
injectDocumentDomain , a new configuration option, can be set to true to re-enable the injection of document.domain setters in Cypress. Addressed in #30770 .
Cypress Component Testing now supports:
React version 19. Addresses #29470 .
Angular version 19. Addresses #30175 .
Next.js version >=15.0.4 . Versions 15.0.0 - 15.0.3 depend on the React 19 Release Candidate and are not officially supported by Cypress, but should still work. Addresses #30445 .
Svelte version 5. Addresses #29641 .
Vite version 6. Addresses #30591 .
Bugfixes:
Elements with display: contents will no longer use box model calculations for visibility, and correctly show as visible when they are visible. Fixed in #29680 . Fixes #29605 .
Fixed a visibility issue when the element is positioned static or relative and the element's offset parent is positioned absolute , a descendent of the ancestor, and has no clippable overflow. Fixed in #29689 . Fixes #28638 .
Fixed a visibility issue for elements with textContent but without a width or height. Fixed in #29688 . Fixes #29687 .
Elements whose parent elements has overflow: clip and no height/width will now correctly show as hidden. Fixed in #29778 . Fixes #23852 .
The CSS pseudo-class :dir() is now supported when testing in Electron. Addresses #29766 .
Fixed an issue where the spec filename was not updating correctly when changing specs in open mode. Fixes #30852 .
cy.origin() now correctly errors when the cy.window() , cy.document() , cy.title() , cy.url() , cy.location() , cy.hash() , cy.go() , cy.reload() , and cy.scrollTo() commands are used outside of the cy.origin() command after the AUT has navigated away from the primary origin. Fixes #30848 . Fixed in #30858 .
Misc:
Dependency Updates:
Upgraded electron from 27.3.10 to 33.2.1 . Addresses #29547 and #30561 .
Upgraded @electron/rebuild from 3.2.10 to 3.7.1 . Addresses #28766 and #30632 .
Upgraded bundled Chromium version from 118.0.5993.159 to 130.0.6723.137 . Addresses #29547 and #30561 .
Updated jQuery from 3.4.1 to 3.7.1 . Addressed in #30345 .
Updated react from 17.0.2 to 18.3.1 and react-dom from 17.0.2 to 18.3.1 . Addresses #30511 .
Upgraded @vue/test-utils from 2.3.2 to 2.4.6 . Addresses #26628 .
Changelog: https://docs.cypress.io/app/references/changelog#13-17-0
Changelog: https://docs.cypress.io/app/references/changelog#13-17-0
Released Dec 17, 2024
Features:
Bugfixes:
Fixed an issue where targets may hang if Network.enable is not implemented for the target. Addresses #29876 .
Updated Firefox userChrome.css to correctly hide the toolbox during headless mode. Addresses #30721 .
Fixed an issue loading the cypress.config.ts file with Node.js version 22.12.0 if it is loaded as an ESM. Addresses #30715 .
Misc:
Dependency Updates:
Changelog: https://docs.cypress.io/app/references/changelog#13-16-1
Changelog: https://docs.cypress.io/app/references/changelog#13-16-1
Released Dec 04, 2024
Bugfixes:
Changelog: https://docs.cypress.io/guides/references/changelog#13-16-0
Changelog: https://docs.cypress.io/guides/references/changelog#13-16-0
Released Nov 19, 2024
Features:
Bugfixes:
Misc:
Changelog: https://docs.cypress.io/guides/references/changelog#13-15-2
Changelog: https://docs.cypress.io/guides/references/changelog#13-15-2
Released Nov 05, 2024
Bugfixes:
Misc:
Dependency Updates:
Updated mobx from 5.15.4 to 6.13.5 and mobx-react from 6.1.8 to 9.1.1 . Addresses #30509 .
Updated @cypress/request from 3.0.4 to 3.0.6 . Addressed in #30488 .
Changelog: https://docs.cypress.io/guides/references/changelog#13-15-1
Changelog: https://docs.cypress.io/guides/references/changelog#13-15-1
Released Oct 24, 2024
Bugfixes:
Patched find-process to fix an issue where trying to clean up browser profiles can throw an error on Windows. Addresses #30378 .
Fixed an issue where requests to the same resource in rapid succession may not have the appropriate static response intercept applied if there are multiple intercepts that apply for that resource. Addresses #30375 .
Misc:
Cypress now consumes geckodriver to help automate the Firefox browser instead of marionette-client . Addresses #30217 .
Cypress now consumes webdriver to help automate the Firefox browser and firefox-profile to create a firefox profile and convert it to Base64 to save user screen preferences via xulstore.json . Addresses #30300 and #30301 .
Spec information is now passed to protocol's beforeSpec to improve troubleshooting when reporting on errors. Addressed in #30316 .
Dependency Updates:
Changelog: https://docs.cypress.io/guides/references/changelog#13-15-0
Changelog: https://docs.cypress.io/guides/references/changelog#13-15-0
Released Sep 25, 2024
Features:
Bugfixes:
Fixed an issue where Firefox was incorrectly mutating the state of click events on checkboxes after Firefox version 129 and up. Addressed in #30245 .
Fixed a regression introduced in 13.13.0 where 'Open in IDE' would not work for filepaths containing spaces and various other characters on Windows. Addresses #29820 .
Misc:
Dependency Updates:
Update @cypress/request from 3.0.1 to 3.0.4 . Addressed in #30194 .
Updated express from 4.19.2 to 4.21.0 . This removes the CVE-2024-43796 , CVE-2024-45590 , and CVE-2024-43800 vulnerabilities being reported in security scans. Addresses #30241 .
Update launch-editor from 2.8.0 to 2.9.1 . Addressed in #30247 .
Updated loader-utils from 1.4.0 to 1.4.2 . This removes the CVE-2022-37601 vulnerability being reported in security scans. Addresses #28208 .
Updated send from 0.17.1 to 0.19.0 . This removes the CVE-2024-43799 vulnerability being reported in security scans. Addressed in #30241 .
Changelog: https://docs.cypress.io/guides/references/changelog#13-14-2
Changelog: https://docs.cypress.io/guides/references/changelog#13-14-2
Released Sep 04, 2024
Bugfixes:
Fixed an issue where Cypress could crash with a WebSocket Connection Closed error. Fixes #30100 .
Fixed an issue where cy.screenshot() was timing out and Cypress was failing to start due to GLib-GIO-ERROR error. Reverts #30109 , the change to allow HiDPI screen for Wayland users. Fixes #30172 and #30160 .
Changelog: https://docs.cypress.io/guides/references/changelog#13-14-1
Changelog: https://docs.cypress.io/guides/references/changelog#13-14-1
Released Aug 29, 2024
Bugfixes:
Your coding agent can read these notes before it upgrades. Set up the MCP server →