Update Non-major updates #66
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
IC3P3/hcss-website!66
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/non-major-updates"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
17.8.0→17.9.017.11.0(+1)24.18.1→24.19.024.18.1→24.19.011.19.0→11.20.011.21.011.19.0→11.20.011.21.08.65.0→8.66.08.67.08.2.0→8.2.1Release Notes
sindresorhus/globals (globals)
v17.9.0Compare Source
5a958ednodejs/node (node)
v24.19.0: 2026-08-03, Version 24.19.0 'Krypton' (LTS), @aduh95Compare Source
Notable Changes
d08872b530] - (SEMVER-MINOR) buffer: implementblob.textStream()(Matthew Aitken) #6403635222948be] - (SEMVER-MINOR) deps: update OpenSSL build config to support compression (Tim Perry) #62217d6ab039f24] - (SEMVER-MINOR) doc: updateblockListstability status to release candidate (alphaleadership) #630501da05fb79d] - doc: markstream.composestable (Matteo Collina) #625623c1636dabf] - (SEMVER-MINOR) esm: add--experimental-import-textflag (Efe) #62300e323e877be] - (SEMVER-MINOR) fs: support caller-suppliedreadFile()buffers (Matteo Collina) #63634c1248c9544] - (SEMVER-MINOR) http: addhttpValidationoption to configure header value validation (RajeshKumar11) #61597a534b65815] - (SEMVER-MINOR) net: supportTCP_KEEPINTVLandTCP_KEEPCNTinsetKeepAlive(Guy Bedford) #63825a23cdec683] - (SEMVER-MINOR) perf_hooks: sample delay per event loop iteration (Pablo Erhard) #629357428b57a37] - (SEMVER-MINOR) src: allow empty--experimental-config-file(Marco Ippolito) #61610e57597173c] - (SEMVER-MINOR) stream: exposeReadableStreamTee(Matteo Collina) #641955396235993] - (SEMVER-MINOR) tls: report negotiated TLS groups (Filip Skokan) #641195e901b5cd9] - (SEMVER-MINOR) tls: addcertificateCompressionoption (Tim Perry) #62217Commits
676467fa9f] - benchmark: trim down the argon2 sets (Filip Skokan) #64218a77a2000b7] - benchmark: add child_process async path baselines (Yagiz Nizipli) #63929dd4482e915] - buffer: remove unreachable overflow check in atob (haramjeong) #60161081c41eb86] - buffer: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) #64169d08872b530] - (SEMVER-MINOR) buffer: implement blob.textStream() (Matthew Aitken) #640366e2f7e6013] - build: remove redundant intermediate node_aix_shared (Chengzhong Wu) #6374787e0675f51] - build: build codecache and snapshot with libnode (Chengzhong Wu) #6362632174a7bae] - build: support setting an emulator from configure script (Ivan Trubach) #5389969cfb2f240] - build: remove duplicated node_use_sqlite and node_use_ffi conditions (Chengzhong Wu) #6362937ac6e8cb5] - build: add manually-dispatched stress-test workflow (Joyee Cheung) #641182424207191] - build: suppress compiler warnings for histogram (Richard Lau) #6398063502b7404] - build,win: fix VS2022 arm64 PGO build (Stefan Stojanovic) #63413fe4e4055d0] - child_process: fix permission model propagation via NODE_OPTIONS (Matteo Collina) #63972aa2f3c066e] - child_process: pass spawn options to the binding positionally (Yagiz Nizipli) #63930fcf32cf77a] - child_process: serialize advanced IPC messages natively (Yagiz Nizipli) #639337907134734] - crypto: reject small-order EdDSA points during verify (Filip Skokan) #64026b505cd5465] - crypto: support non-byte WebCrypto lengths and cSHAKE (Filip Skokan) #639880f54a872e2] - crypto: share WebCrypto method and usage helpers (Filip Skokan) #63975824ec11c05] - crypto: refactor keyObject.toCryptoKey() and SubtleCrypto.getPublicKey() (Filip Skokan) #6362273aba92689] - crypto: coerce -0 to +0 before native calls (Filip Skokan) #63556c83b79874e] - crypto: reject invalid raw key imports (Filip Skokan) #63134934fda64b9] - crypto: improve accuracy of SubtleCrypto.supports (Filip Skokan) #63104e392e1f791] - crypto: fix large DH generator validation (Tobias Nießen) #64092e75a363e70] - crypto: use EVP_MAC for HMAC on OpenSSL >=3 (Filip Skokan) #63942adbaf7af9b] - crypto: make webcrypto aliasKeyFormat directional (Filip Skokan) #63910bb1aea8897] - crypto: fix unhandled error in Hash._transform (Haram Jeong) #6326112c87732c1] - crypto: handle cipher context allocation failures (Tian Teng) #63542858496b453] - crypto: deduplicate X509 subject matching logic (Tobias Nießen) #636449a29cb0964] - crypto: fix warnings in test_node_crypto.cc (Maya Lekova) #634908bb536066d] - crypto: optimize normalizeAlgorithm dispatch hot path (Filip Skokan) #62756329e5496ff] - crypto,tls: do not ignore BN_get_word error (Tobias Nießen) #6389597b7a3f9c7] - debugger: add --max-hit option to probe mode (Joyee Cheung) #637049098585c5e] - debugger: add more logs to probe mode (Joyee Cheung) #6366359cca26cd5] - debugger: surface inspector failures in probe mode (Joyee Cheung) #634372922290eae] - debugger: disambiguate probe location binding (Joyee Cheung) #632866fb2c2c7e2] - debugger: lazily wait for initial break output (Trivikram Kamat) #63969688e792551] - debugger: defer probe pause handling until startup (Trivikram Kamat) #636081ac93cc05a] - debugger: await initialization after run and restart (Trivikram Kamat) #6360792a909cf72] - debugger,test: deflake resume failure test and add debug logs (Joyee Cheung) #635248b37af8b11] - deps: V8: backportbef0d9c(Joyee Cheung) #621328832126422] - deps: V8: cherry-pick64b36b4(Dan Carney) #6171275990c2cd6] - deps: update googletest to8b53336(Node.js GitHub Bot) #641818500c7ba86] - deps: update sqlite to 3.53.3 (Node.js GitHub Bot) #64180dc78091b45] - deps: c-ares: cherry-pick8ba37af(René) #64110873cc72125] - deps: update googletest to0b1e895(Node.js GitHub Bot) #640391d3d166538] - deps: update acorn to 8.17.0 (Node.js GitHub Bot) #6390135222948be] - (SEMVER-MINOR) deps: update OpenSSL build config to support compression (Tim Perry) #62217e40cee5f79] - deps: upgrade npm to 11.17.0 (npm team) #6385785c6d46606] - deps: add ngtcp2_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞) #63821d2ea8b7a8c] - deps: update googletest to7140cd4(Node.js GitHub Bot) #6377525b4d57bb6] - deps: update sqlite to 3.53.2 (Node.js GitHub Bot) #63774a96368e4c7] - deps: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot) #63773b59f1f5f37] - deps: update amaro to 1.1.10 (Node.js GitHub Bot) #636700b3b56ee95] - deps: update googletest to8736d2c(Node.js GitHub Bot) #63669aa67b5b9c4] - dgram: add synchronous Socket connectSync() (Guy Bedford) #63932ef38374875] - dgram: add synchronous Socket.prototype.bindSync() (Guy Bedford) #638386edc3a9967] - dgram: skip dns.lookup() for literal IP addresses (Ruben Bridgewater) #64133d4cfe2d8ac] - dns: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan) #6355691c9ce5a45] - doc: improvefs.StatFsproperties descriptions (aymanxdev) #6257854e21675fa] - doc: fix inconsistencies in CJS code snippets (Antoine du Hamel) #6319964c23daa76] - doc: remove typo comma from man page (Vas Sudanagunta) #63080bc943cd34a] - doc: update Http2SecureServer.on("timeout") default value (YuSheng Chen) #64187a46bc452a6] - doc: add note on visibility of CI failures to new contributor guide (Stewart X Addison) #64256c0fb52506c] - doc: clarify HTTP/1.1 response ordering (Matteo Collina) #64213d3073a7ba6] - doc: recommend node-stress-single-test for flaky tests (Trivikram Kamat) #64223bb9951ead0] - doc: fix typo in examples (Vas Sudanagunta) #64184fe674e96fc] - doc: clarify defense-in-depth issues (Matteo Collina) #64215faad042184] - doc: add guide and answers to FAQs for first-time contributors (Joyee Cheung) #6368579d685adf3] - doc: updateHttp2Server.close&Http2SecureServer.close(YuSheng Chen) #63298744e40e05e] - doc: update list of people inSECURITY.md(Richard Lau) #64152185f57c4a4] - doc: add missing option to man page (Richard Lau) #641568933303568] - doc: fix callback example import in fs docs (Kamal Rawal) #639123a0549dacb] - doc: fix keepAliveTimeout default in http.createServer options (Jahanzaib iqbal) #639745a35e48d08] - doc: add sxa GPG key (ed25519) (Stewart X Addison) #6419366e7f815f1] - doc: add aduh95 to last security release steward (Antoine du Hamel) #63981a7e35040dd] - doc: fix typo in util.md (Daijiro Wachi) #63961d74b3a7e90] - doc: clarify callback exceptions (Matteo Collina) #63939b7a8f8fabd] - doc: fix incorrect test runner mock examples (Kimaswa Emmanuel Yusufu) #63656f11aa690cd] - doc: fix typo in cli.md (Daijiro Wachi) #63883df85f50269] - doc: fix typo in vm.md (Daijiro Wachi) #63881a00a567175] - doc: fix typo in packages.md (Daijiro Wachi) #63882206c1b8437] - doc: fix a/an article typos in module, util, and dns (Daijiro Wachi) #63766e3e5ef1cff] - doc: update npm supported versions link (hojeong park) #63672e3c4852413] - doc: fix AES-OCB IV length in SubtleCrypto.supports example (Anshika Jain) #637170b3fbc82d7] - doc: add webstreams to args forpipelinefromstream/promises(David Sanders) #6362862078a8328] - doc: fix "used to sent" → "used to send" in http2 (Daijiro Wachi) #63700fd74eefb23] - doc: clarify tty raw mode applies to input processing only (Muhammad Zeeshan) #6343842cd7e47de] - doc: add worker_threads history entries (Bob Put) #63545d6ab039f24] - (SEMVER-MINOR) doc: updateblockListstability status to release candidate (alphaleadership) #6305056bdd87378] - doc: move hyperlinks outside of text blocks (Aviv Keller) #634931da05fb79d] - doc: mark stream.compose stable (Matteo Collina) #625627bb6dab70c] - doc,crypto: mark argon2 and encap/decap as stable (Filip Skokan) #639241a4edb3c22] - doc,lib: align WebCrypto names with spec (Filip Skokan) #635183c1636dabf] - (SEMVER-MINOR) esm: add--experimental-import-textflag (Efe) #62300e0f211ca79] - events: improveaddAbortListenerperf by caching options object (Raz Luvaton) #52367a124429b36] - fs: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied) #63709e323e877be] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #63634a41b4824d7] - fs: prevent spurious recursive watch events on prefix siblings (Marco) #63095c63e00e3a5] - fs: ignore deleted dirs in recursive watch scan (Trivikram Kamat) #63686d3d7cd05e3] - fs: coerce -0 to +0 in mode flags and watch intervals (Filip Skokan) #635566f6387ecb3] - gyp: update deps gypfiles (Nad Alaba) #63117592544af44] - http: document and validate options.path when it's in absolute-form (Joyee Cheung) #64108c1248c9544] - (SEMVER-MINOR) http: add httpValidation option to configure header value validation (RajeshKumar11) #6159785a223bf15] - http: fix drain event with cork/uncork (David Evans) #640388b060a9628] - inspector: fix crash when writing to closed inspector socket (ympark2011) #64209e68a3d33ac] - inspector: fix inspector.close() documented behavior (Chengzhong Wu) #63837d3682930b7] - lib: fix missing lazyDOMException import (Filip Skokan) #64033af9ea9cfcf] - lib: reject string "0" in validatePort when allowZero is false (Daijiro Wachi) #64174cd1ea26110] - lib: use__proto__: nullwhen callingObjectDefineProperty(Antoine du Hamel) #642395b264398ce] - lib: lazily initialize kEvents and kHandlers maps (Guilherme Araújo) #63702823efe8c71] - lib: improve control abstraction coverage in frozen intrinsics (Renegade334) #636987f4af5568f] - lib: add Iterator global to primordials (Renegade334) #63698c8f3f5e5a5] - lib: makeNavigator#languagegetter throw on invalidthis(Mohamed Sayed) #636011ebbbd59cf] - lib: optimize webidl conversion options (Filip Skokan) #6275688590d1bb7] - meta: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot[bot]) #637260ea9cb9630] - meta: bump actions/upload-artifact from 7.0.0 to 7.0.1 (dependabot[bot]) #62850f7275a0864] - meta: fix linter warning instale.yml(Antoine du Hamel) #642813a77d21d8c] - meta: bump actions/cache from 5.0.5 to 6.1.0 (dependabot[bot]) #6424884e2836c95] - meta: bump github/codeql-action/autobuild from 4.36.1 to 4.36.2 (dependabot[bot]) #6424709f800eec6] - meta: bump github/codeql-action/analyze from 4.36.1 to 4.36.2 (dependabot[bot]) #642466df1f97e64] - meta: bump codecov/codecov-action from 6.0.1 to 7.0.0 (dependabot[bot]) #64244737eb89651] - meta: bump rtCamp/action-slack-notify from 2.3.3 to 2.4.0 (dependabot[bot]) #64243dac3cd8b8f] - meta: bump github/codeql-action/init from 4.36.1 to 4.36.2 (dependabot[bot]) #64242108a6bc481] - meta: bump github/codeql-action/upload-sarif from 4.36.1 to 4.36.2 (dependabot[bot]) #6424034d09a725d] - meta: clarify V8 flags are outside threat model (Matteo Collina) #64224944d9bc25f] - meta: move one or more collaborators to emeritus (Node.js GitHub Bot) #64057cc22555402] - meta: update status of past strategic initiatives (Joyee Cheung) #63480da7a21931e] - meta: speed up stale bot (Aviv Keller) #640757bfcf7ca56] - meta: bump github/codeql-action from 4.35.3 to 4.36.1 (dependabot[bot]) #63724db6c983cdd] - meta: bump actions/cache from 5.0.4 to 5.0.5 (dependabot[bot]) #628479e4f1339d1] - meta: bump codecov/codecov-action from 6.0.0 to 6.0.1 (dependabot[bot]) #6372592c98d3ade] - meta: bump actions/stale from 10.2.0 to 10.3.0 (dependabot[bot]) #63728bbd3ffde89] - meta: bump step-security/harden-runner from 2.19.0 to 2.19.4 (dependabot[bot]) #63727a6dd675c82] - module: enable import support for addons by default (Chengzhong Wu) #64221fb2ccb15a1] - module: use file: URL as sourceURL for type-stripped CommonJS (Joyee Cheung) #63705b9e17dc424] - net: early TCP binding via synchronous net.BoundSocket (Guy Bedford) #63951a534b65815] - (SEMVER-MINOR) net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) #63825c55dd030e6] - net: coerce -0 to +0 in BlockList prefixes (Filip Skokan) #63556a23cdec683] - (SEMVER-MINOR) perf_hooks: sample delay per event loop iteration (Pablo Erhard) #62935f08b83bc1d] - perf_hooks: add NODE_PERFORMANCE_GC_MINOR_MARK_SWEEP constant (Attila Szegedi) #638778d58e1b415] - process: fix finalization cleanup ref tracking (Trivikram Kamat) #64087c757e3ef59] - sqlite: do not leave database open after failed open (Yagiz Nizipli) #6385487064a096b] - sqlite: fix stack-use-after-scope with function callback (ndossche) #636407428b57a37] - (SEMVER-MINOR) src: allow empty --experimental-config-file (Marco Ippolito) #61610d7946c9c07] - src: add test flag to config file (Marco Ippolito) #60798a642657d71] - src: rename config file testRunner to test (Marco Ippolito) #60798818b43d09e] - src: do not enable wasm trap handler if there's not enough vmem (Joyee Cheung) #62132af5e1a9729] - src: fix escaping of single quotes in task runner (Antoine du Hamel) #640898a5d3bc168] - src: abstract tracing agent for both legacy and perfetto (Chengzhong Wu) #64053ce6f29e45b] - src: avoid redundant call tostd::get_if<>()(Tobias Nießen) #6409496478050f2] - src: omit unconvertible names in cjs_lexer::Parse (Yagiz Nizipli) #639430147ed746e] - src: guard OpenSSL compression header include (Filip Skokan) #640098d2858a9c4] - src: handle empty MaybeLocal in cjs_lexer::Parse (Yagiz Nizipli) #63885e5289d180f] - src: do not track weakBaseObjects as childrens ofRealms (Anna Henningsen) #63842e8352ff754] - src: allow tracking children inMemoryTrackerwith weak edges (Anna Henningsen) #63842a408f279c5] - src: use C++14 deprecated attribute forNODE_DEPRECATED(Anna Henningsen) #637554b5eb7b72d] - src: add cleanup hooks tonode::ObjectWrap(Anna Henningsen) #6364244976c6071] - src: fix edge case when deflateInit2() fails with Z_VERSION_ERROR (Nora Dossche) #634765b3bb284f3] - src: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can Altin) #633857cdad636c4] - src: fix crash when reading length on Storage.prototype (Mohamed Sayed) #63529c438250c68] - stream: cut per-chunk overhead in WHATWG streams (Matteo Collina) #64252291c127947] - stream: reduce allocations on WHATWG streams hot paths (Matteo Collina) #638763d91aeb434] - stream: optimize pipeTo promise handling (Matteo Collina) #63572fcbff00a44] - stream: preserve half-open duplexes in async iteration (Efe) #64275e57597173c] - (SEMVER-MINOR) stream: expose ReadableStreamTee (Matteo Collina) #64195a48edf40e8] - stream: proxy first own method in Readable.wrap() (Daijiro Wachi) #64048f58c5bafcf] - stream: fix Writable.toWeb() desiredSize for non-object-mode (Matteo Collina) #629867261276f45] - stream: fix Utf8Stream stall after full write of multi-byte data (Daijiro Wachi) #639641558986b78] - stream: only pass the expected number of parameters to callbacks (Antoine du Hamel) #63909edef89ba6a] - stream: fix dropped first chunk in Utf8Stream buffer mode (Daijiro Wachi) #63833915e3e2f42] - stream: check done before backpressure in stream reader (Daijiro Wachi) #636992d29628b5b] - test: update WPT for WebCryptoAPI to03a1476(Node.js GitHub Bot) #6390089e23b70c4] - test: deflake test-debugger-probe-timeout (Joyee Cheung) #6354754ca514414] - test: make blob desiredSize assertion robust (Trivikram Kamat) #6410601cbe530eb] - test: update WPT for urlpattern to11a459a(Node.js GitHub Bot) #640376fcd3cf516] - test: improve lcov reporter snapshot diagnostics (Trivikram Kamat) #64049f50a55d7e5] - test: keep finalization close fixture ref alive (Trivikram Kamat) #640853085714530] - test: fix typo from overriden to overridden (parkhojeong) #634039f5347e8df] - test: mark hr-time WPT flaky on macos15-x64 (Trivikram Kamat) #6405444b4fe4246] - test: use one-off agent in http consumed timeout test (Trivikram Kamat) #640522f567edaca] - test: fix flaky test-runner coverage threshold test (Trivikram Kamat) #64051a56fbb2d36] - test: tolerate duplicate watch change events (Trivikram Kamat) #63937b636f4769c] - test: mark test-debugger-run-after-quit-restart as flaky on macOS (Matteo Collina) #64006ba23eb9717] - test: update WPT for url tod4598eb(Node.js GitHub Bot) #63899bc420f20d8] - test: update WPT for urlpattern to23aac92(Node.js GitHub Bot) #63898d2c9c07af8] - test: add tests for 3 methods in utils (Daijiro Wachi) #637654e00c8ec2e] - test: mark SEA tests flaky on linux arm debug (Trivikram Kamat) #63743a17cf06d12] - test: validate ERR_INVALID_THIS for scheduler methods (Daijiro Wachi) #63764d59d7fdd16] - test: add coverage outside SEA (Daijiro Wachi) #6374471a32d31bf] - test: update WPT for urlpattern to2f28df5(Node.js GitHub Bot) #6377128c77ab174] - test: make Brotli 16GB test wait for backpressure (Trivikram Kamat) #633899a81921d4a] - test: add regression test for usingObjectWrapin worker (Mohamed Akram) #6364288ab61f2f8] - test: accept SIGILL aborts in async-hooks tests (Trivikram Kamat) #63687b4f5c86463] - test: add more test cases for pathToFileURL (Rafael Gonzaga) #63293812a66f0ac] - test: update test426-fixtures to2965987(Node.js GitHub Bot) #636682bf0de838d] - test: cover webcrypto prototype pollution systematically (Filip Skokan) #63520bec6856ae8] - test,debugger: add test for type stripping in debugger probe mode (Joyee Cheung) #63748a2b9095e03] - test_runner: avoid recompiling coverage globs for every file (sangwook) #6367502fbff446f] - test_runner: cacheshouldSkipFileCoverageresult per URL (sangwook) #63675094869354a] - test_runner: ignore erased TS lines in coverage (Matteo Collina) #6351068edc2b009] - test_runner: fix suite diagnostic chanel end (Moshe Atlow) #63533659d5bf068] - test_runner: add parentId to test events with testId (Moshe Atlow) #63435eaebeb8b88] - test_runner: fix hooks test context (Moshe Atlow) #63285d03d96889b] - test_runner: add tags option and tag-name filter (Chemi Atlow) #63221e8c3db1364] - test_runner: addgetTestContext()(Moshe Atlow) #62501345c591d10] - test_runner: filter execArgv fallback for child tests (Trivikram Kamat) #640562f47fb23bf] - test_runner: improve coverage failure diagnostics (Trivikram Kamat) #64050260cf1ac89] - test_runner: add timestamp to JUnit reporter testsuites (sangwook) #6402924140eafdf] - test_runner: remove unused shuffleArrayWithSeed (Daijiro Wachi) #63847b7fdb4891a] - test_runner: fix watch cwd with isolation none (Trivikram Kamat) #63690e48b307e09] - timers: reuse Timeout objects in setStreamTimeout (Matteo Collina) #642545396235993] - (SEMVER-MINOR) tls: report negotiated TLS groups (Filip Skokan) #64119a653e9bb57] - tls: handle large RSA exponents in X.509 cert (Tobias Nießen) #640935e901b5cd9] - (SEMVER-MINOR) tls: add certificateCompression option (Tim Perry) #622173abcfa723c] - tls: route event listener exceptions through error handlers (Antoine du Hamel) #63822eaba4cd59d] - tools: bump the eslint group in /tools/eslint with 8 updates (dependabot[bot]) #642497d7ea1dbca] - tools: update c-ares updater script (Antoine du Hamel) #64194976827cd71] - tools: validate version number in release proposal commit message lint (Antoine du Hamel) #64070cc0c586b52] - tools: update sccache to v0.16.0 (Michaël Zasso) #63078f0a35fa56a] - tools: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md (dependabot[bot]) #63948dafbd23240] - tools: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint (dependabot[bot]) #639470ae1552650] - tools: update the llhttp updater script (Antoine du Hamel) #638193623586d1f] - tools: align Bash snippets in GHA withlint-shconventions (Antoine du Hamel) #6382964b130ce1d] - tools: bump the eslint group in /tools/eslint with 7 updates (dependabot[bot]) #637304900cac251] - tools: fix zlib updater script (Antoine du Hamel) #637078edf3abafc] - typings: add typing for crypto (Filip Skokan) #64122d5be94e820] - url: fix URLSearchParams(null) to prudce null= per spec (Marco) #63782ee66a3851c] - util: fix OOM in inspect color stack formatting (Ijtihed Kilani) #64022e26f183699] - util: fix scientific notation formatting (Daijiro Wachi) #638237993e3e476] - util: fix -0 formatting when numericSeparator is enabled (Daijiro Wachi) #6381538758a7789] - util: remove style caches from styleText slow path (Guilherme Araújo) #6370646a0ca256a] - watch: print name of changed file that triggers restart (Marco) #63781e1582818ad] - watch: cancel pending restart on shutdown (Trivikram Kamat) #633839a208668b0] - zlib: validate flush king for all streams (Ic3b3rg) #63746928981d803] - zlib: validate flush kind for brotli streams (Ic3b3rg) #63746fd0fb00164] - zlib: expose rejectGarbageAfterEnd option (Filip Skokan) #64023e334d30b4c] - zlib: reject trailing gzip members in web streams (Filip Skokan) #640237433c3df2e] - zlib: coerce -0 to +0 for crc32 seeds (Filip Skokan) #63556actions/node-versions (node)
v24.19.0: 24.19.0Compare Source
Node.js 24.19.0
pnpm/pnpm (npm:pnpm)
v11.20.0: pnpm 11.20Compare Source
Minor Changes
Security fix. Affects projects using
namedRegistrieson pnpm 11.1.0–11.19.x. It is semi-breaking for those projects — see "If you use named registries" below.The lockfile recorded no marker for which registry a package came from. Packages were keyed by
name@versionalone, and entry lookup went throughrefToRelative(ref, name), so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a singlepackages:entry and whichever resolved first decided the tarball every consumer got.That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell.
Packages resolved from a named registry are now recorded under registry-qualified keys (
<name>@​<registryName>:<version>, e.g.foo@work:1.0.0), so each registry gets its own entry and the lockfile pins which one a dependency came from.The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use
namedRegistriessees no difference, and older pnpm versions keep reading the file.If you use named registries
Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating.
Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it.
There is no setting to keep the old behavior: the old shape is the vulnerability.
Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the
namedRegistriessetting on demand.To use named registries, map your aliases in
pnpm-workspace.yaml:New built-in
npmjs:aliasnpmjs:now resolves tohttps://registry.npmjs.org/with no configuration, alongside the existinggh:alias for GitHub Packages. It pins a dependency to the public registry even whenregistrypoints elsewhere, such as an internal proxy:npm:cannot do this — it is the alias protocol (npm:<name>@​<range>) and resolves through whateverregistrypoints at.If you mirror or proxy npmjs, point the alias at your mirror:
Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on
registry.npmjs.orgis verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL,minimumReleaseAge, ortrustPolicycheck runs. Overriding the alias is the same escape hatch GHES users already have forgh.Every alias the lockfile references must stay in
namedRegistries: reading an entry whose alias is gone fails withERR_PNPM_MISSING_NAMED_REGISTRYrather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it.Named registry aliases that shadow a reserved dependency specifier prefix (
file,link,workspace,runtime,npm,jsr, ...) are now rejected withERR_PNPM_RESERVED_NAMED_REGISTRY_NAMEinstead of being silently shadowed by the corresponding resolver.pnpm licensesandpnpm sbomnow keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purlrepository_urlqualifier.Patch Changes
An empty
http-proxy,https-proxy,proxy, orno-proxyvalue — from the.npmrc,pnpm-workspace.yaml, the CLI, or theHTTP_PROXY/HTTPS_PROXY/PROXY/NO_PROXYenvironment variables — no longer fails the install withERR_PNPM_INVALID_PROXY. Empty settings read as unset, so a shell exportingHTTP_PROXY=disables the proxy, and an emptyproxy=in the.npmrcno longer suppressesHTTPS_PROXY#13533.proxy=falsein the.npmrcorproxy: falseinpnpm-workspace.yamlnow turns proxying off instead of being read as a proxy host namedfalse.falseandnullonhttps-proxy/http-proxy/no-proxyread as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim.The env lockfile no longer pins
@pnpm/exealongsidepnpmwhen the wanted pnpm version is 12 or newer. From v12 the unscopedpnpmpackage is itself the native executable, so@pnpm/exeis not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it.lexCompareandnerfDartare now published as@pnpm/text.ordinal-comparatorand@pnpm/config.registry-auth-key. Use these instead of@pnpm/util.lex-comparatorand@pnpm/config.nerf-dart.Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs.
Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when
minimumReleaseAgeis active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison.Security:
pnpm rebuildnow refuses a lockfile whosepackageskey carries a path traversal in the package name (e.g.../../../escaped@1.0.0), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected withERR_PNPM_INVALID_DEPENDENCY_NAME.Platinum Sponsors
Gold Sponsors
typescript-eslint/typescript-eslint (typescript-eslint)
v8.66.0Compare Source
This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
vitejs/vite (vite)
v8.2.1Compare Source
Bug Fixes
sharedPlugins: true(#23184) (15f0307)input(#23135) (b4bf596)Performance Improvements
Documentation
@defaultfor build.minify (#23177) (ef02435)Miscellaneous Chores
Code Refactoring
Tests
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
c5915b20dcbf2c8e4455