SkillByAIOpen interactive version →

Lesson 25 / 25

A Vue Release Checklist

Review before shipping.

Questions to ask

Do components follow one-way data flow, with props in and events out? Is derived state computed rather than duplicated, and are watchers cleaned up? Do lists use stable keys? Is shared client state in Pinia and server data fetched with clear loading and error states? Are routes lazy-loaded and guards backed by server-side authorisation? Does vue-tsc pass, do component tests cover key behaviour, and do end-to-end tests cover critical journeys? Is the bundle analysed, are heavy components async, and is v-html avoided for untrusted content? Is the production build served with SPA fallback or deployed through Nuxt with SSR as planned?

The checklist

Use it in reviews.

[ ] props down, events up; no mutation of props
[ ] derived values use computed; watchers and listeners cleaned up
[ ] v-for lists have stable :key values (not indexes for changing lists)
[ ] shared client state in Pinia; storeToRefs when destructuring
[ ] every request renders loading, error and empty states
[ ] routes lazy-loaded; guards for UX plus server-side auth checks
[ ] no v-html with untrusted content (XSS)
[ ] vue-tsc --noEmit passes in CI
[ ] Vitest + Vue Test Utils for components; E2E for key journeys
[ ] bundle analysed; heavy components async; KeepAlive / v-memo where measured
[ ] history mode server fallback to index.html, or Nuxt SSR configured
[ ] dependencies on supported versions of Vue, Vue Router and Pinia

Never render untrusted HTML

v-html bypasses Vue's escaping. Rendering user-supplied content with it opens the door to cross-site scripting; sanitise it or render it as text.

Quick check: Which item belongs on a Vue release checklist?

  • Route guards replace server-side authorisation
  • Props are mutated directly in children for speed
  • Lists rendered with v-for use stable unique keys
  • v-html is used for all user comments
Answer

Lists rendered with v-for use stable unique keys — Correct, safe and maintainable apps.