chore(deps): update npm non-breaking updates#44
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
a43afaf to
27897c8
Compare
5f123b7 to
92a500d
Compare
6297457 to
090c028
Compare
1007740 to
3c030a1
Compare
3c030a1 to
e4afc56
Compare
d0427cf to
ad5f32f
Compare
69cb500 to
f9211d8
Compare
fa493a5 to
997bd0c
Compare
29795c1 to
5170b79
Compare
b3da770 to
8815cd2
Compare
690275c to
51a84b4
Compare
|
|
|
1 similar comment
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR contains the following updates:
^0.9.6→^0.9.9^1.15.24→^1.15.30^25.5.2→^25.6.0^8.58.1→^8.59.0^8.58.1→^8.59.0^17.4.1→^17.4.2^17.4.1→^17.4.2^5.1.0→^5.2.1>=18.4→>=18.20.8^3.8.1→^3.8.3^4.60.1→^4.60.2^6.0.2→^6.0.3^8.58.1→^8.59.0Release Notes
scalar/scalar (@scalar/express-api-reference)
v0.9.9Patch Changes
v0.9.8v0.9.7swc-project/swc (@swc/core)
v1.15.30Compare Source
Bug Fixes
(deploy) Fix musl binding test workflow (#11804) (c30a522)
(deploy) Build package ts before Linux GNU binding tests (#11806) (a3d3ef3)
(es/jsx) Preserve quoted JSX attribute newlines (#11796) (9fe56c8)
(es/minifier) Support full ES version parsing in minify (#11800) (af1f08f)
(es/module) Add opt-in symlink-preserving resolver (#11801) (6028240)
(es/parser) Allow return type annotation on Flow constructors (#11790) (d66b29c)
(es/parser) Support Flow anonymous keyof indexers (#11792) (452c4e5)
(es/parser) Add Flow strip RN and RNW regression corpus (#11799) (23a9109)
Documentation
Features
v1.15.26Compare Source
typescript-eslint/typescript-eslint (@typescript-eslint/eslint-plugin)
v8.59.0Compare Source
🚀 Features
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.58.2Compare Source
🩹 Fixes
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
typescript-eslint/typescript-eslint (@typescript-eslint/parser)
v8.59.0Compare Source
This was a version bump only for parser to align it with other projects, there were no code changes.
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
v8.58.2Compare Source
🩹 Fixes
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
motdotla/dotenv (dotenv)
v17.4.2Compare Source
nodejs/node (node)
v18.20.8: 2025-03-27, Version 18.20.8 'Hydrogen' (LTS), @richardlauCompare Source
Notable Changes
This release updates OpenSSL to 3.0.16 and root certificates to NSS 3.108.
Commits
f737a79073] - async_hooks,inspector: implement inspector api without async_wrap (Gabriel Bota) #51501fce923ba69] - build: update gcovr to 7.2 and codecov config (Benjamin E. Coe) #540198b7ffd807c] - build: fix compatibility with V8'sdepot_tools(Richard Lau) #57330ee9a343413] - crypto: update root certificates to NSS 3.108 (Node.js GitHub Bot) #57381738bf8aea4] - crypto: update root certificates to NSS 3.104 (Richard Lau) #5568169d661d591] - deps: update undici to v5.29.0 (Matteo Collina) #5755759fcf43b0e] - deps: update corepack to 0.32.0 (Node.js GitHub Bot) #572651b72869503] - deps: update archs files for openssl-3.0.16 (Node.js GitHub Bot) #57335a566560235] - deps: upgrade openssl sources to quictls/openssl-3.0.16 (Node.js GitHub Bot) #5733550c4e1da2f] - doc: add missingdeprecatedbadges infs.md(Yukihiro Hasegawa) #57384c3babb4671] - doc: update Xcode version used for arm64 and pkg (Michaël Zasso) #57104784da606a6] - doc: fix link and history ofSourceMapsections (Antoine du Hamel) #57098f5dbceccbe] - test: update error code in tls-psk-circuit for for OpenSSL 3.4 (sebastianas) #56420v18.20.7: 2025-02-20, Version 18.20.7 'Hydrogen' (LTS), @aduh95Compare Source
Notable Changes
ea5eb0e98b] - crypto: update root certificates to NSS 3.107 (Node.js GitHub Bot) #56566Commits
bb2977ca6c] - build: use glob for dependencies of out/Makefile (Richard Lau) #5578992896945b8] - build: support python 3.13 (Chengzhong Wu) #53190ea5eb0e98b] - crypto: update root certificates to NSS 3.107 (Node.js GitHub Bot) #56566d03a23577d] - deps: V8: cherry-pick26fd1df(Shu-yu Guo) #5587353bb21b093] - deps: V8: backportae5a4db(Shu-yu Guo) #558735eb6dfe284] - deps: update zlib to 1.3.0.1-motley-82a5fec (Node.js GitHub Bot) #55980734515a0f7] - deps: update zlib to 1.3.0.1-motley-7e2e4d7 (Node.js GitHub Bot) #54432d64cc98324] - deps: update simdutf to 5.6.4 (Node.js GitHub Bot) #562559eab21dd1d] - deps: update simdutf to 5.6.3 (Node.js GitHub Bot) #559732e3367b46a] - deps: update simdutf to 5.6.2 (Node.js GitHub Bot) #55889df74d66207] - deps: update simdutf to 5.6.1 (Node.js GitHub Bot) #55850ade37ee0b3] - deps: update acorn to 8.14.0 (Node.js GitHub Bot) #55699a3c367adbd] - deps: update corepack to 0.31.0 (Node.js GitHub Bot) #567952cff6a8428] - deps: update corepack to 0.30.0 (Node.js GitHub Bot) #559778b8c9a2cf5] - doc: update macOS and Xcode versions for releases (Michaël Zasso) #56337706af28113] - doc: add "Skip to content" button (Antoine du Hamel) #56750634a6b3a14] - doc: improve accessibility of expandable lists (Antoine du Hamel) #56749f0b60c5bf9] - doc: fix arrow vertical alignment in HTML version (Akash Yeole) #5219391cce27ebb] - doc: remove flicker on page load on dark theme (Dima Demakov) #50942522fbb00a8] - doc: make theme consistent across api and other docs (Dima Demakov) #508771486465520] - doc: save user preference for JS flavor (Vidar Eldøy) #49526d74cff7e59] - doc: rename possibly confusing variable and CSS class (Antoine du Hamel) #495364829d976fe] - doc: add main ARIA landmark to API docs (Rich Trott) #498826c4ce1f1d4] - doc: add navigation ARIA landmark to doc ToC (Rich Trott) #4988233548f8c1f] - doc: add history entries for JSON modules stabilization (Antoine du Hamel) #55855e12bdf6141] - meta: bumpactions/upload-artifactfrom 4.4.3 to 4.6.0 (dependabot[bot]) #568616f44ef388b] - meta: bump actions/upload-artifact from 4.4.0 to 4.4.3 (dependabot[bot]) #55685ae39211117] - meta: bump actions/upload-artifact from 4.3.4 to 4.4.0 (dependabot[bot]) #547034cf80b37c7] - meta: bumpactions/upload-artifactfrom 4.3.3 to 4.3.4 (dependabot[bot]) #541664d402b79cb] - meta: bumpactions/download-artifactfrom 4.1.7 to 4.1.8 (dependabot[bot]) #541671c01f93497] - meta: bump actions/upload-artifact from 4.3.1 to 4.3.3 (dependabot[bot]) #527856558a516ec] - meta: bump actions/download-artifact from 4.1.4 to 4.1.7 (dependabot[bot]) #52784dd70860ec8] - meta: bump actions/download-artifact from 4.1.3 to 4.1.4 (dependabot[bot]) #523144a24d92a45] - meta: bump actions/upload-artifact from 4.3.0 to 4.3.1 (dependabot[bot]) #51941655b9071b9] - meta: bump actions/download-artifact from 4.1.1 to 4.1.3 (dependabot[bot]) #519380e6ad795aa] - meta: bump actions/download-artifact from 4.1.0 to 4.1.1 (dependabot[bot]) #5164461babc5037] - meta: bump actions/upload-artifact from 4.0.0 to 4.3.0 (dependabot[bot]) #516438b16d80029] - meta: update artifact actions to v4 (Michaël Zasso) #51219d47e8cb86d] - test: do not use deprecated import assertions (Antoine du Hamel) #5587306c523d693] - test: marktest-inspector-stop-profile-after-doneas flaky (Antoine du Hamel) #57001dafea86962] - test: marktest-perf-hooksas flaky on macOS (Antoine du Hamel) #570018e53f1f43d] - test: mark test-inspector-multisession-ws as flaky (Antoine du Hamel) #57001350eb50bbe] - test: marktest-performance-functionas flaky (Antoine du Hamel) #57001a1f428a343] - test: skiptest-perf-hookson SmartOS (Antoine du Hamel) #57001199f52fcc0] - test: make test-crypto-hash compatible with OpenSSL > 3.4.0 (Jelle van der Waa) #56160b08ce67d48] - test: compare paths on Windows without considering case (Early Riser) #539936e84d211a1] - test: deflake test-perf-hooks.js (Joyee Cheung) #49892a7f565fc7f] - tools: fix failinglint-shworkflow (Antoine du Hamel) #56995v18.20.6: 2025-01-21, Version 18.20.6 'Hydrogen' (LTS), @RafaelGSSCompare Source
This is a security release.
Notable Changes
Dependency update:
Commits
c03ad5ed63] - build: use rclone instead of aws CLI (Michaël Zasso) #556178232463294] - build, tools: drop leading/fromr2dir(Richard Lau) #53951b26bcd3394] - build, tools: copy release assets to staging R2 bucket once built (flakey5) #5139456df127b7b] - build,tools: simplify upload of shasum signatures (Michaël Zasso) #53892a63e9372ed] - (CVE-2025-22150) deps: update undici to v5.28.5 (Matteo Collina) nodejs-private/node-private#657da2d177f91] - (CVE-2025-23084) path: fix path traversal in normalize() on Windows (Tobias Nießen) nodejs-private/node-private#5556cc8d58e6f] - (CVE-2025-23085) src: fix HTTP2 mem leak on premature close and ERR_PROTO (RafaelGSS) nodejs-private/node-private#650v18.20.5: 2024-11-12, Version 18.20.5 'Hydrogen' (LTS), @aduh95Compare Source
Notable Changes
ac37e554a5] - esm: mark import attributes and JSON module as stable (Nicolò Ribaudo) #55333Commits
c2e6a8f215] - benchmark: fix napi/ref addon (Michaël Zasso) #532334c2e07aaac] - build: pin doc workflow to Node.js 20 (Richard Lau) #557556ba4ebd060] - build: fix build with Python 3.12 (Luigi Pinca) #50582c50f01399e] - crypto: ensure invalid SubtleCrypto JWK data import results in DataError (Filip Skokan) #550415c46782137] - crypto: make deriveBits length parameter optional and nullable (Filip Skokan) #536016e7274fa53] - crypto: reject dh,x25519,x448 in {Sign,Verify}Final (Huáng Jùnliàng) #53774d2442044db] - crypto: rejectEd25519/Ed448 in Sign/Verify prototypes (Filip Skokan) #5234093670de499] - deps: upgrade npm to 10.8.2 (npm team) #537998531c95587] - deps: upgrade npm to 10.8.1 (npm team) #53207fd9933ea0f] - deps: upgrade npm to 10.8.0 (npm team) #5301403852495d7] - deps: update simdutf to 5.6.0 (Node.js GitHub Bot) #553793597be4146] - deps: update simdutf to 5.5.0 (Node.js GitHub Bot) #5443452d2c03738] - deps: update simdutf to 5.3.4 (Node.js GitHub Bot) #54312dd882ac483] - deps: update simdutf to 5.3.1 (Node.js GitHub Bot) #541965fb8e1b428] - deps: update simdutf to 5.3.0 (Node.js GitHub Bot) #53837c952fd886d] - deps: update simdutf to 5.2.8 (Node.js GitHub Bot) #52727a1ae050ed5] - deps: update simdutf to 5.2.6 (Node.js GitHub Bot) #5272796ec48da7f] - deps: update brotli to 1.1.0 (Node.js GitHub Bot) #5080411242bcfb4] - deps: update zlib to 1.3.0.1-motley-71660e1 (Node.js GitHub Bot) #5346464f98a9869] - deps: update zlib to 1.3.0.1-motley-c2469fd (Node.js GitHub Bot) #534644b815550e0] - deps: update zlib to 1.3.0.1-motley-68e57e6 (Node.js GitHub Bot) #53464f6b2f68ce7] - deps: update zlib to 1.3.0.1-motley-8b7eff8 (Node.js GitHub Bot) #53464e151ebef86] - deps: update zlib to 1.3.0.1-motley-e432200 (Node.js GitHub Bot) #53464637a306e02] - deps: update zlib to 1.3.0.1-motley-887bb57 (Node.js GitHub Bot) #53464569a739569] - deps: update zlib to 1.3.0.1-motley-209717d (Node.js GitHub Bot) #53156033f1e2ba5] - deps: update zlib to 1.3.0.1-motley-4f653ff (Node.js GitHub Bot) #53052aaa857fc01] - deps: update ada to 2.8.0 (Node.js GitHub Bot) #53254d577321877] - deps: update acorn to 8.13.0 (Node.js GitHub Bot) #5555855b3c8a41f] - deps: update acorn-walk to 8.3.4 (Node.js GitHub Bot) #5495050a9456f1e] - deps: update acorn-walk to 8.3.3 (Node.js GitHub Bot) #53466f56cfe776b] - deps: update acorn to 8.12.1 (Node.js GitHub Bot) #53465fce3ab686d] - deps: update archs files for openssl-3.0.15+quic1 (Node.js GitHub Bot) #5518446c782486e] - deps: upgrade openssl sources to quictls/openssl-3.0.15+quic1 (Node.js GitHub Bot) #551844a18581dc3] - deps: update corepack to 0.29.4 (Node.js GitHub Bot) #5484567e98831ab] - deps: update archs files for openssl-3.0.14+quic1 (Node.js GitHub Bot) #54336c60c6630af] - deps: upgrade openssl sources to quictls/openssl-3.0.14+quic1 (Node.js GitHub Bot) #54336935a506377] - deps: update corepack to 0.29.3 (Node.js GitHub Bot) #54072dbdfdd0226] - deps: update corepack to 0.29.2 (Node.js GitHub Bot) #53838395ee44608] - deps: update corepack to 0.28.2 (Node.js GitHub Bot) #532536ba8bc0618] - deps: update c-ares to 1.29.0 (Node.js GitHub Bot) #5315581c3260cd2] - deps: update corepack to 0.28.1 (Node.js GitHub Bot) #52946e4739e9aa6] - doc: only apply content-visibility on all.html (Filip Skokan) #535104d2ac5d98f] - doc: move release key for Myles Borins (Richard Lau) #540591c4decc998] - doc: add release key for aduh95 (Antoine du Hamel) #55349a4f6f0918f] - doc: add names next to release key bash commands (Aviv Keller) #52878c679348f83] - errors: usedetermineSpecificTypein more error messages (Antoine du Hamel) #495803059262185] - esm: fix broken assertion inlegacyMainResolve(Antoine du Hamel) #55708ac37e554a5] - esm: mark import attributes and JSON module as stable (Nicolò Ribaudo) #5533384b0ead758] - esm: fix hook name in error message (Bruce MacNaughton) #504660092358d00] - http: handle multi-value content-disposition header (Arsalan Ahmad) #50977d814fe935c] - src: account for OpenSSL unexpected version (Shelley Vohr) #540386615fe5db1] - src: fix dynamically linked OpenSSL version (Richard Lau) #53456d6114cb2e2] - test: fix test when compiled without engine support (Richard Lau) #53232ac3a39051c] - test: fix test-tls-junk-closes-server (Michael Dawson) #55089c8520ff7d2] - test: fix OpenSSL version checks (Richard Lau) #535039824827937] - test: update tls test to support OpenSSL32 (Michael Dawson) #550301a4d497936] - test: adjust tls-set-ciphers for OpenSSL32 (Michael Dawson) #55016341496a5a2] - test: add asserts to validate test assumptions (Michael Dawson) #5499737a2f7eaa4] - test: adjust key sizes to support OpenSSL32 (Michael Dawson) #5497275ff0cdf66] - test: update test to support OpenSSL32 (Michael Dawson) #54968b097d85dfe] - test: adjust test-tls-junk-server for OpenSSL32 (Michael Dawson) #54926e9997388a6] - test: adjust tls test for OpenSSL32 (Michael Dawson) #54909c7de027adb] - test: fix test test-tls-dhe for OpenSSL32 (Michael Dawson) #5490368156cbae1] - test: fix test-tls-client-mindhsize for OpenSSL32 (Michael Dawson) #54739d5b73e5683] - test: increase key size for ca2-cert.pem (Michael Dawson) #545995316314755] - test: update TLS test for OpenSSL 3.2 (Richard Lau) #54612a1f0c87859] - test: fix test-tls-client-auth test for OpenSSL32 (Michael Dawson) #54610e9e3306426] - test: use assert.{s,deepS}trictEqual() (Sonny) #542081320fb9475] - test: update TLS trace tests for OpenSSL >= 3.2 (Richard Lau) #53229cc3cdf7cc0] - test: check against run-time OpenSSL version (Richard Lau) #53456fc43c6803e] - test: update TLS tests for OpenSSL 3.2 (Richard Lau) #53384627d3993f0] - test: fix unreliable assumption in js-native-api/test_cannot_run_js (Joyee Cheung) #518989f521f456e] - test: update tests for OpenSSL 3.0.14 (Richard Lau) #533730fb652eba9] - tools: update gyp-next to v0.16.1 (Michaël Zasso) #50380fa72b2c2de] - tools: skip ruff on tools/gyp (Michaël Zasso) #50380v18.20.4: 2024-07-08, Version 18.20.4 'Hydrogen' (LTS), @RafaelGSSCompare Source
This is a security release.
Notable Changes
Commits
85abedf1ff] - lib,esm: handle bypass network-import via data: (RafaelGSS) nodejs-private/node-private#522eccd63b865] - src: handle permissive extension on cmd check (RafaelGSS) nodejs-private/node-private#596v18.20.3: 2024-05-21, Version 18.20.3 'Hydrogen' (LTS), @richardlauCompare Source
Notable Changes
This release fixes a regression introduced in Node.js 18.19.0 where
http.server.close()was incorrectly closing idle connections.A fix has also been included for compiling Node.js from source with newer versions of Clang.
The list of keys used to sign releases has been synchronized with the current list from the
mainbranch.Updated dependencies
Commits
0c260e10e7] - deps: update zlib to 1.3.0.1-motley-7d77fb7 (Node.js GitHub Bot) #525161152d7f919] - deps: update zlib to 1.3.0.1-motley-24c07df (Node.js GitHub Bot) #52199755399db9d] - deps: update zlib to 1.3.0.1-motley-24342f6 (Node.js GitHub Bot) #52123af3e32073b] - deps: update ada to 2.7.8 (Node.js GitHub Bot) #52517e4ea2db58b] - deps: update c-ares to 1.28.1 (Node.js GitHub Bot) #5228514e857bea2] - deps: update corepack to 0.28.0 (Node.js GitHub Bot) #526167f5dd44ca6] - deps: upgrade npm to 10.7.0 (npm team) #5276778f84ebb09] - deps: update ngtcp2 to 1.3.0 (Node.js GitHub Bot) #517961f489a3753] - deps: update ngtcp2 to 1.2.0 (Node.js GitHub Bot) #515843034968225] - deps: update ngtcp2 to 1.1.0 (Node.js GitHub Bot) #513191aa9da467f] - deps: add nghttp3/**/.deps to .gitignore (Luigi Pinca) #5140028c0c78c9a] - deps: update ngtcp2 and nghttp3 (James M Snell) #512918fd5a35364] - deps: upgrade npm to 10.5.2 (npm team) #524582c53ff31c9] - deps: update acorn-walk to 8.3.2 (Node.js GitHub Bot) #5145712f28f33c2] - deps: update acorn to 8.11.3 (Node.js GitHub Bot) #51317dddb7eb3e0] - deps: update acorn-walk to 8.3.1 (Node.js GitHub Bot) #50457c86550e607] - deps: update acorn-walk to 8.3.0 (Node.js GitHub Bot) #504579500817f66] - deps: update acorn to 8.11.2 (Node.js GitHub Bot) #504607a8c7b6275] - deps: update ada to 2.7.7 (Node.js GitHub Bot) #52028b199889943] - deps: update corepack to 0.26.0 (Node.js GitHub Bot) #52027052b0ba0c6] - deps: upgrade npm to 10.5.1 (npm team) #52351209823d3af] - deps: update simdutf to 5.2.4 (Node.js GitHub Bot) #524735114cbe18a] - deps: update simdutf to 5.2.3 (Yagiz Nizipli) #52381be30309ea0] - deps: update simdutf to 5.0.0 (Daniel Lemire) #52138b56f66e250] - deps: update simdutf to 4.0.9 (Node.js GitHub Bot) #51655a9f3b9d9d1] - deps: update nghttp2 to 1.61.0 (Node.js GitHub Bot) #523951b6fa70620] - deps: update nghttp2 to 1.60.0 (Node.js GitHub Bot) #519483c9dbbf4d4] - deps: update nghttp2 to 1.59.0 (Node.js GitHub Bot) #51581e28316da54] - deps: update nghttp2 to 1.58.0 (Node.js GitHub Bot) #50441678641f470] - deps: V8: cherry-pickd15d49b(Bo Anderson) #523371147fee7d9] - doc: remove ableist language from crypto (Jamie King) #520635e93eae972] - doc: add release key for marco-ippolito (marco-ippolito) #522576689a98488] - http: remove closeIdleConnections function while calling server close (Kumar Rishav) #5233671616e8a8a] - node-api: make tsfn accept napi_finalize once more (Gabriel Schulhof) #51801d9d9e62474] - src: avoid draining platform tasks at FreeEnvironment (Chengzhong Wu) #51290e5fc8ec9fc] - test: skip v8-updates/test-linux-perf (Michaël Zasso) #49639351ef189ca] - test: v8: Add test-linux-perf-logger test suite (Luke Albao) #503525cec2efc31] - test: reduce the number of requests and parsers (Luigi Pinca) #502405186e453d9] - test: deflake test-http-regr-gh-2928 (Luigi Pinca) #49574c60cd67e1c] - test: skip test for dynamically linked OpenSSL (Richard Lau) #52542v18.20.2: 2024-04-10, Version 18.20.2 'Hydrogen' (LTS), @RafaelGSSCompare Source
This is a security release.
Notable Changes
child_process.spawnwithout shell option enabled on WindowsCommits
6627222409] - src: disallow direct .bat and .cmd file spawning (Ben Noordhuis) [nodeConfiguration
📅 Schedule: (in timezone Asia/Kolkata)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.