What's new
- Cookies out of the box — the same for Express and Fastify, no adapter-specific packages.
- CSRF protection and security headers built into the framework.
- File uploads in Fastify — interceptors backed by
@fastify/multipart. - Multiple global route prefixes, for example for different API versions.
- Fixes: Redis client reconnects in microservices, middleware after transient providers, the
ParseDatePipedefault value.
What to watch out for
This is a minor release with no breaking changes — upgrade from 12.0 directly. If you already use third-party packages for CSRF protection or security headers, make sure the built-in protection doesn't duplicate them.
How to upgrade
- Update all
@nestjs/*packages to the same version and check the migration guide. - Check the Node.js version on servers and in CI.
- Run the API unit and e2e tests before rolling out.
We build and maintain NestJS and Node.js backends: we will upgrade the framework and dependencies, cover it with tests and roll out without downtime.
Source: official release announcement.
