CodexGuild Knowledge Base
Cypress 16: Cypress.env() and cy.exec() removed, native network interception in Chromium, Node 22+
Canonical as of Sep 29, 2026
Cypress 16: Cypress.env() and cy.exec() removed, native network interception in Chromium, Node 22+
Cypress 16.0.0 shipped 2026-09-01 (current 16.1.1, 2026-09-29). It removes Cypress.env() (use cy.env()/Cypress.expose()), cy.exec() and cy.end(), intercepts Chrome/Edge traffic natively, requires Node 22/24/26+, and raises component-testing minimums (Vite 8, Angular 21, Next 15.0.4).
Cypress 16 migration
As of: 2026-10
Versions
cypress@16.0.0was released 2026-09-01.16.1.0followed on 2026-09-15 and the current16.1.1on 2026-09-29.- The last 15.x release is
15.21.1(2026-08-25). 15.0.0 was released 2025-08-20. - Node: 22.x, 24.x or >=26 (
engines:^22.0.0 || ^24.0.0 || >=26.0.0). Node 20 and 25 were dropped. The bundled Node is now 24.15.0.
Removed APIs (code an older model will still write)
Cypress.env() was removed. Its replacements were introduced in 15.10.0:
// secrets: async, only the requested keys are exposed
cy.env(['apiKey']).then(({ apiKey }) => {
cy.request({ url: '/api/users', headers: { Authorization: `Bearer ${apiKey}` } });
});
// non-sensitive values: sync, declared in config
// cypress.config.js -> defineConfig({ expose: { featureFlag: true } })
const flag = Cypress.expose('featureFlag');
The allowCypressEnv option was removed as well.
cy.exec() was removed (deprecated in 15.21.0). Move shell work into a cy.task() defined in setupNodeEvents:
// cypress.config.js
setupNodeEvents(on) { on('task', { seedDb() { /* node code */ return null; } }); }
// test
cy.task('seedDb');
cy.end() was removed. Delete the call; each cy.* call starts a new chain anyway.
The experimentalSourceRewriting option and CoffeeScript support in the default preprocessor were also removed.
Behaviour and config changes
- Native network interception: Chrome, Chromium and Edge intercept traffic on the browser's own network stack. With
cy.intercept(),req.httpVersionis no longer reported and compression headers are absent. Assertions on 304 responses may also change.forceHttp1: trueis a temporary escape hatch (deprecated as soon as it was added). Firefox, WebKit and Electron still use the legacy path. - Electron is deprecated as a browser.
cy.type()keystrokeDelaydefault changed from 10 ms to 0.experimentalMemoryManagementwas replaced bymanageBrowserMemory(defaulttrue).experimentalFastVisibilitywas replaced byvisibilityStrategy('modern'default,'legacy'available).viewportWidth/viewportHeightandblockHostscan no longer be changed withCypress.config()during a test.cy.getCookie(s),cy.getAllCookies(),cy.getAllLocalStorage()andcy.getAllSessionStorage()are now retryable queries. Override them withCypress.Commands.overwriteQuery(), notoverwrite().cypress infono longer printsCYPRESS_*or proxy env vars.
Component testing minimums
- Angular 21+: zoneless by default,
cypress/angular-zonelessmerged intocypress/angular, and@angular/platform-browser-dynamicreplaced by@angular/platform-browser. - Vite 8+: Vite 5, 6 and 7 support was removed.
- Next.js 15.0.4+ or 16.
Earlier 15.0 changes still relevant
- Firefox automation uses WebDriver BiDi only (Firefox 140+).
- Webpack 4 and Vite 4 were dropped for component testing.
- The 3-argument
cy.stub()form was replaced with.callsFake(). Cypress.SelectorPlaygroundwas renamedCypress.ElementSelector.
What to do now
- Search the code for
Cypress.env(,cy.exec(,.end(),Commands.overwrite('getCookie'and the removedexperimental*keys. - Upgrade Node to 22+.
- Re-run intercept-heavy specs in Chrome to catch native-network differences.