
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@tanstack/vue-router
Advanced tools

🤖 Type-safe router w/ built-in caching & URL state management for Vue!
| Suffix/Pattern | Purpose |
|---|---|
.route.ts | Route configuration (loader, validateSearch, head, etc.) |
.component.vue | The component rendered for the route |
.errorComponent.vue | Error boundary component for the route |
.notFoundComponent.vue | Not found component for the route |
.lazy.ts | Lazy-loaded route configuration |
_layout prefix | Layout routes that wrap child routes |
_ suffix (e.g., posts_.$postId) | Unnested routes (break out of parent layout) |
(groupName) directory | Route groups (organizational, don't affect URL) |
$param | Dynamic route parameters |
src/routes/
├── __root.ts # Root route config
├── __root.component.vue # Root layout component
├── __root.notFoundComponent.vue # Global not found component
├── index.route.ts # "/" route config
├── index.component.vue # "/" component
├── posts.route.ts # "/posts" route config
├── posts.component.vue # "/posts" layout component
├── posts.index.component.vue # "/posts" index component
├── posts.$postId.route.ts # "/posts/:postId" route config
├── posts.$postId.component.vue # "/posts/:postId" component
├── posts.$postId.errorComponent.vue # Error boundary for post
├── posts_.$postId.edit.route.ts # "/posts/:postId/edit" (unnested)
├── (group)/ # Route group (no URL impact)
│ ├── _layout.route.ts # Layout for group
│ ├── _layout.component.vue
│ └── inside.component.vue # "/inside"
└── 대한민국.component.vue # Unicode routes supported
FAQs
Modern and scalable routing for Vue applications
The npm package @tanstack/vue-router receives a total of 22,160 weekly downloads. As such, @tanstack/vue-router popularity was classified as popular.
We found that @tanstack/vue-router demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.