Version 0.3.6 tries to replace several React choices at once
Vista.js gives React 19 developers a familiar app/ directory, file-based pages and APIs, Server Components by default, client-component boundaries, SSR, and a single CLI for development and production. The resemblance to Next.js is intentional and stated in the first sentence of the README. Vista adds its own typed API layer, auth generator, middleware, deployment output, AI agents, and retrieval helpers. That is a wide promise for a repository created less than one month ago.
Two engines sit under the same commands. The default path uses webpack for RSC and SSR, while Flashpack uses Rust-backed code and stores runtime state separately. The v0.3.6 release made new scaffolds smaller by keeping theme and deployment files in the engine. Published packages include @vistagenic/vista, create-vista-app, and the internal vista-native bridge. The last package is where our clean-container run stopped.
What happened when we ran it
Our sandbox installed commit e9fb4f4 in 47 seconds with 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. Pnpm added 1,294 packages, using 675 MB on disk. The checkout contained 781 files, about 63,812 source lines, and occupied 4.3 MB before installation. Npm audit reported 0 known vulnerabilities across the installed dependency tree.
The build failed after 13 seconds. Its final lines show the vista-native@0.1.0 workspace running napi build --platform --release, followed by ERR_PNPM_RECURSIVE_RUN_FIRST_FAIL and exit status 1. The tail does not include the underlying compiler, linker, platform, or package error, so assigning a cause would be guesswork. The reliable finding is that the documented monorepo build did not finish in our fresh container.
The test command failed after 9 seconds. A summary line reported 102 passed checks, then Node raised MODULE_NOT_FOUND while loading crates/vista-napi/index.js from scripts/test-rust-bridge.cjs. The overall result is a failure. Those 102 earlier checks show that meaningful JavaScript validation ran before the bridge step, but they cannot turn a broken required module into a green suite.
Three open defects reach production paths in v0.3.6
Open issue 155 targets commit e9fb4f4 and reproduces Anthropic streaming dropping tool_use blocks. In that report, Agent.stream() finishes without executing the requested local tool, while the non-streaming path preserves it. An agent application can therefore produce a normal-looking completion while silently skipping work. A proposed pull request exists, but the issue remained open on September 30.
Issue 82 reproduces the generated Netlify SSR handler placing HTTP status lines, headers, and streamed chunk markers inside the Lambda body. Issue 152 reports two more server-runtime failures: several Set-Cookie headers collapse to the last value, and malformed JSON can escape as a server error on a legacy API route. These are issue-tracker reproductions, not failures from our sandbox, but each concerns output or state a production caller depends on.
The active bug hunt explains the 81-item queue
GitHub showed 25 open issues and 56 open pull requests on October 1, for the repository's combined count of 81. A framework-wide bounty opened on September 20 and invited reports across RSC, auth, AI, RAG, deployments, and both engines. That campaign produced unusually detailed reproductions and competing fixes. It also makes the issue count a picture of rapid discovery rather than 81 ordinary support tickets. The queue still needs maintainers to confirm, merge, release, and close the defects.
The default branch was pushed on September 21, one day after v0.3.6, while issue and pull-request activity continued through September 30. Vista had 2,384 stars and 47 forks on October 1. Those dates show attention. They do not show that the reported fixes have reached users, because the latest release predates many of the open reports and our measured commit is the same commit named in several reproductions.
The custom license and native bridge narrow the safe audience
Vista's license permits use, modification, publishing, and distribution, but it is a project-specific text with attribution and no-false-authorship conditions. GitHub reports no recognized SPDX identifier. A company that requires MIT, Apache-2.0, or another approved standard license should send the text through its normal review before adoption. The custom terms are especially relevant for forks and redistributed framework builds.
Vista is interesting because one scaffold can reach pages, APIs, auth, AI tools, RAG, and several deployment targets. Today, that breadth is also the risk surface. Our 1,294-package install reached a failed native build, the full test command did not pass, and current issues touch streamed agents, Netlify responses, and cookies. Use v0.3.6 to study or contribute. Choose a narrower, established framework for production until those exact checks turn green.

