What scalar/scalar shipped
Written by FoxPlug from public releases; not affiliated with Scalar. An automatic summary of the public release, pull request and commit data of github.com/scalar/scalar. Scalar did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Added SEO pages, tools and technical fixes to scalar.com to improve search rankings for API documentation, SDK generation and MCP server searches. Pull request #10384
- Added support for OpenAPI 3.2 additionalOperations across workspace store, API client, API reference, and mock server. Pull request #10186
- Added OpenAPI 3.2 querystring parameter support for editing whole-query values with media type and example validation. Pull request #10189
- Added an interactive SDK Generator demo to the SDK overview page showing generation from OpenAPI document to release pull request. Pull request #9953
- Mock-server XML responses now use schema-aware serialization instead of json2xml, preserving attributes, namespaces and root naming. Release
- Fixed prototype pollution vulnerability in workspace-store nested object operations by limiting JSON traversal to own properties. Pull request #10342
- Restricted AsyncAPI external references to prevent resolution outside source directories or to internal network addresses. Pull request #10343
- Fixed client-side rendering to escape inline configuration data preventing script element termination. Pull request #10344
- Fixed desktop login callback to use OS-assigned loopback port instead of fixed port 3000 and corrected CORS configuration. Pull request #10352
- Optimized openapi-to-markdown loading performance by linking references after value coercion. Pull request #10356
Why it matters
This week added OpenAPI 3.2 support for querystring parameters and additionalOperations, bringing the API client and reference implementations up to spec. Security fixes addressed prototype pollution and external reference handling, while performance improvements reduced memory usage during large API description processing.
Changelog entry
- Support OpenAPI 3.2 querystring parameters with content-based serialization and media type examples Pull request #10189
- Add OpenAPI 3.2 additionalOperations support to workspace store, API client, API reference and mock server Pull request #10186
- Generate schema-aware XML examples with attributes, namespaces and root naming in requests, responses, snippets and mocks Release
- Connect SDK samples to example switcher while keeping selected language consistent Pull request #10310
- Honor OpenAPI 3.2 parameter examples using dataValue and serializedValue in editor and generated requests Pull request #10322
- Show discriminator mapping values in schema selectors with payload values that select them Pull request #10317
- Prevent prototype pollution in nested object operations by limiting traversal to own properties Pull request #10342
- Restrict AsyncAPI external references to prevent resolution outside source directories Pull request #10343
- Fix desktop login to use OS-assigned loopback port and allow configured dashboard origin for CORS Pull request #10352
- Escape inline configuration data in client-side rendering to prevent script element termination Pull request #10344
Scalar ships OpenAPI 3.2 querystring and additionalOperations support, XML example generation, desktop login fixes, and security patches for prototype pollution and external references.
This week Scalar added OpenAPI 3.2 support for querystring parameters and additionalOperations across the API client, reference, and mock server. Security improvements prevent prototype pollution in nested object operations and restrict AsyncAPI external references. Performance optimizations reduce memory usage when processing large API descriptions. An interactive SDK Generator demo now appears on the overview page, and desktop login no longer conflicts with port 3000.
Week of September 14, 2026
What shipped
- @scalar/openapi-to-markdown@1.0.0 now generates Markdown directly from syntax trees, removing Vue server rendering and HTML conversion to achieve 1.4–9.5x faster document loading with 26–67% lower peak memory. Release
- @scalar/workspace-store@0.63.0 adds getDocumentRevision() to track document writes, letting consumers validate cached schema derivations in constant time instead of walking subtrees. Release
- Workspace store proxy now materializes paths only on writes and returns primitives and cached child proxies first, reducing allocations on every property read. Pull request #10261
- Server store now exposes getResolvedDocument(name) so server renders can read whole documents through one non-reactive reference while browsers load chunks. Pull request #10257
- API client now supports the OpenAPI 3.2 QUERY request method, including request bodies, workspace navigation, and server chunks. Pull request #10173
- API reference now shows AsyncAPI message examples with a picker and copy button, handling duplicate names and empty values. Pull request #10171
- API client adds a line wrapping toggle for request and response bodies to handle long single-line strings like JWT tokens without horizontal scrolling. Pull request #9912
- API client adds a generate example from schema button so users can see auto-generated request bodies when custom examples exist. Pull request #10072
- API client now supports response interception through onResponseReceived hooks to replace body, status, and headers before display. Pull request #10102
- Release 2026-09-16 ships updates across api-client, api-reference, helpers, localization, oas-utils and other packages. Release
Why it matters
The workspace store changes reduce memory overhead and improve caching efficiency for schema operations. Markdown generation and AsyncAPI support expand the scope of documents Scalar can handle efficiently. New request features in the API client—line wrapping, example generation, and response interception—make working with APIs more practical.
Changelog entry
- @scalar/openapi-to-markdown@1.0.0: Generate Markdown directly from syntax trees, removing Vue rendering and HTML conversion pipeline for 1.4–9.5x faster loads and 26–67% lower peak memory Release
- @scalar/workspace-store@0.63.0: Add getDocumentRevision() counter for constant-time schema derivation validation Release
- Workspace store: Cheaper schema walks using parent-link chains and cached child proxies, reducing per-read allocations Pull request #10261
- Server store: Expose getResolvedDocument(name) for non-reactive whole-document reads during server render Pull request #10257
- API client: Support OpenAPI 3.2 QUERY request method with request bodies and server chunks Pull request #10173
- API reference: Show AsyncAPI message examples with picker and copy button Pull request #10171
- API client: Add line wrapping toggle for request and response bodies Pull request #9912
- API client: Add generate example from schema button alongside custom examples Pull request #10072
- API client: Support response interception via onResponseReceived hooks Pull request #10102
- API reference: Resolve AsyncAPI message traits to show inherited headers and fields Pull request #10168
Markdown generation 1.4–9.5x faster, workspace store cheaper on reads, AsyncAPI examples in the reference, and OpenAPI 3.2 QUERY support shipping this week.
This week: @scalar/openapi-to-markdown hits 1.0 with direct syntax tree rendering (1.4–9.5x faster, 26–67% less memory). Workspace store optimizations cut allocations on every property read. API client gains line wrapping for long values, auto-generated examples from schemas, and response interception. API reference now handles AsyncAPI message examples and traits. OpenAPI 3.2 QUERY method support lands in the client.