What nestjs/nest shipped
Written by FoxPlug from public releases; not affiliated with NestJS. An automatic summary of the public release, pull request and commit data of github.com/nestjs/nest. NestJS did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Released v12.1.0 with microservices connection retry fixes, core dependency detection improvements, and route handler name preservation. Release
- Added built-in, adapter-agnostic cookie handling in common and core packages. Pull request #17834
- Added built-in CSRF protection and security headers for common, core, and Fastify. Pull request #17836
- Added file upload interceptors for Fastify backed by @fastify/multipart. Pull request #17835
- Fixed circular dependency detection to work across more than two providers. Pull request #17871
- Fixed Kafka client to keep newer connection when a stale one fails. Pull request #17869
- Fixed route handler names being preserved instead of showing as anonymous functions for tracing and profiling tools. Pull request #17840
- Fixed ParseArrayPipe to reject non-numeric items when items type is Number. Pull request #17876
- Fixed multer limits option to merge key-by-key instead of overriding wholesale between global and per-route options. Pull request #17818
- Released v11.2.6 with multer security update and error code mapping fixes for Express. Release
Why it matters
v12.1.0 ships critical microservices reliability improvements across Kafka, Redis, RabbitMQ, and NATS, plus new security and cookie features. Multiple core fixes address dependency detection, middleware handling, and provider overrides. These changes improve both stability for distributed systems and developer experience with better diagnostics.
Changelog entry
- v12.1.0: Microservices connection retry fixes for Kafka, Redis, RabbitMQ, and NATS; circular dependency detection; route handler name preservation Release
- [core] detect circular dependencies across more than two providers Pull request #17871
- [microservices] keep newer kafka connection when stale one fails Pull request #17869
- [microservices] keep newer nats connection when stale one fails Pull request #17878
- [microservices] let rmq client retry after failed connect Pull request #17865
- [core] preserve route handler names in registered handlers Pull request #17840
- [common,core] add built-in adapter-agnostic cookie handling Pull request #17834
- [common,core,fastify] built-in CSRF protection and security headers Pull request #17836
- [fastify] add file upload interceptors backed by @fastify/multipart Pull request #17835
- [common] reject non-numeric items in ParseArrayPipe with items Number Pull request #17876
- [platform-express] merge multer limits key-by-key in interceptors Pull request #17818
- v11.2.6: multer security update (CVE-2026-88932) and error code mapping fixes Release
v12.1.0 is out: microservices connection resilience across all transports, CSRF protection, cookie handling, and fixes for circular deps, route names, and provider overrides.
v12.1.0 released with significant improvements to microservices reliability. The Kafka, Redis, RabbitMQ, and NATS clients now properly retry after failed connections. New security features include built-in CSRF protection and cookie handling. Core framework fixes address circular dependency detection across multiple providers, route handler name preservation for profiling tools, and dependency injection edge cases. These updates strengthen both distributed system stability and development workflows.