Update Non-major updates #76
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
IC3P3/hcss-website!76
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/non-major-updates"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.62.1→1.63.024.13.3→24.13.424.13.6(+1)10.9.1→10.10.010.11.024.20.0→24.21.024.20.0→24.21.011.25.0→11.27.011.27.11.62.1→1.63.011.25.0→11.27.011.27.18.69.0→8.70.08.2.2→8.3.0Release Notes
microsoft/playwright (@playwright/test)
v1.63.0Compare Source
🔒 Test locks
Tests that access a shared resource — an external service, a global account setting — can now declare a named
lock.Tests that share a lock name never run concurrently, across files, workers and projects, while
everything else keeps running in parallel:
A test can hold multiple locks, and test.describe() accepts a
lockfor the whole group.Learn more about test locks.
🪟 Locate across frames
page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the
subtree, so you no longer need to locate the iframe first:
The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it
matches elements in several frames.
👁️ Visible-only locators
New locator.visible() returns a locator that matches only visible elements. It is the recommended
replacement for the
:visibleCSS pseudo-class:🧾 Step params and subtitles
Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments,
and test.step() accepts
subtitleandparamsoptions for your own steps:Reporters receive them via testStep.subtitle and testStep.params. For Playwright API
steps, the subtitle is the locator or the navigation url — for example,
Clickwith subtitlegetByRole('button').Both are rendered next to the step title in the trace viewer and the HTML report.
🖼️ Aria and screen snapshots in traces
The
snapshotsoption of tracing.start() and the testOptions.trace fixture option now accept anobject selecting what to capture on every action:
With aria and screen snapshots recorded, the new Display Aria mode in the trace viewer shows the action screenshot
side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.
New APIs
Browser and Context
httpCredentialsnow also accepts an array of credentials. The first entry matching the request origin is used, and entries without an origin match any request.opfsincludes the origin private file system in the storage state, so it can be persisted and restored into later contexts.Locators
mode,depthandboxesoptions.json():Test runner
--add-reportercommand line option appends a reporter on top of the ones configured inplaywright.config, instead of replacing them like--reporterdoes.omitTagsoption for thelist,line,dot,githubandjunitreporters suppresses the tags that are automatically appended to test titles.Command line
npx playwright install --no-removekeeps the browsers of other Playwright installations instead of removing them.npx playwright codegen --http-credentialsrecords against pages behind HTTP authentication.Miscellaneous
perfettoreporter writes a Trace Event Format file for the Perfetto UI orchrome://tracing, rendering the test run as a timeline with a lane per worker.Announcements
@playwright/experimental-ct-react,@playwright/experimental-ct-react17and@playwright/experimental-ct-vuepackages will no longer be updated. Follow the migration guide to move to the stories model introduced in 1.62. Story ids passed to fixtures.mount() can now be typed through the generatedStoriesregistry.Browser Versions
This version was also tested against the following stable channels:
eslint/eslint (eslint)
v10.10.0Compare Source
Features
264b434feat: adddandvflags tono-unexpected-multiline(#21305) (Gihyeon Jeong / 정기현)c6cc6c5feat: checkObject.prototypeproperty names innew-cap(#21269) (crimsonjay0)5661fa6feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)Bug Fixes
bb47dc6fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)427ac0afix: use format strings in debug calls (#21247) (Francesco Trotta)9d81532fix: support__proto__in/* exported */comments (#21261) (sethamus)87e0a08fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)8e2cb14fix:new-capfalse positive forUTCcalls withproperties: false(#21275) (Pixel)9f4a364fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)Documentation
2417caddocs: Update README (GitHub Actions Bot)9cecb8adocs: document\ccontrol letter escapes in no-control-regex (#21286) (한국)8724829docs: update compat table links (#21263) (fnx)5634542docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)Chores
b3d876bchore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)1696682ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))2c7f5d6chore: update github/codeql-action action to v4.37.9 (#21296) (renovate[bot])3c753f1chore: update eslint (#21289) (renovate[bot])1c73469chore: update ecosystem plugins (#21280) (ESLint Bot)08a02betest: add error locations tono-extra-boolean-cast(#21266) (lumir)77bb1dbchore: update github/codeql-action action to v4.37.8 (#21270) (renovate[bot])007e81aci: skip EMFILE test on Node.js 26 (#21265) (lumir)0430280chore: improve ecosystem tests compatibility on Windows (#21178) (crimsonjay0)nodejs/node (node)
v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @aduh95Compare Source
Notable Changes
71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #639496274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #6554253cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #657890529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #6502441c7062b81] - (SEMVER-MINOR) net: improve performance ofnet.BlockList(James M Snell) #649745197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #6541635c635b032] - (SEMVER-MINOR) util: add non-throwingMIMEType.parse(James M Snell) #64965Commits
84d706cb9b] - assert: improve documentation wording (Kamal Rawal) #6495390d127db33] - (SEMVER-MINOR) benchmark: add --analyze mode to compare.js (James M Snell) #65416ad1d7884c3] - benchmark: add test-only and mock timers cases (Luan Muniz) #640971d8f045914] - benchmark: applyhighWaterMarkin webstreamspipe-to(Matteo Collina) #65138ed7ba3c993] - benchmark: complete the sqlite is-transaction fix (Edy Silva) #65218c8837e1aa3] - benchmark: add test runner hooks and options (Luan Muniz) #637542ba8661e23] - buffer: prevent string write offset overflow (Matteo Collina) #65043cc9ee6c2ae] - buffer: treat detached ArrayBuffers as empty (Archkon) #645045a5d73e4c5] - build: pass target architecture to small-icu genccode (ulofiai) #65095273e72d1a5] - build: deprecate always enabled--enable-static(Chengzhong Wu) #6510389a67246e3] - build: check FIPS option value in node.gyp (Filip Skokan) #649822d21f41cd5] - build: handle malformed OpenSSL macros (Filip Skokan) #64982f62bc0f862] - build,win: add PGO workload scripts (Stefan Stojanovic) #6369633d0c7dc12] - child_process: keep SIGWINCH from killing on Win (Kirill Saied) #6451071106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495419af8b86d] - crypto: fix missing error checks on ASN1_STRING_to_UTF8() (Nora Dossche) #652008029383f3f] - crypto: use available BoringSSL APIs (Filip Skokan) #65423a9bd780e19] - crypto: remove obsolete BoringSSL shims (Filip Skokan) #654237defefad3f] - crypto: read WebCrypto inputs through primordials (Filip Skokan) #651156ed1e38627] - crypto: fix disabling FIPS mode (Filip Skokan) #64982afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #639499b9dd6e9cf] - debugger: wait for target startup (Filip Skokan) #6519407faaeeffd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #6565353cba013c7] - deps: update undici to 7.29.1 (Node.js GitHub Bot) #657890268ca547c] - deps: update archs files for openssl-3.5.8 (Node.js GitHub Bot) #655426274fccbd9] - deps: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #655426bdcd121fa] - deps: update zlib to 1.3.2.1-motley-8002e91 (Node.js GitHub Bot) #65316c2aa446b6d] - deps: update simdjson to 4.6.7 (Node.js GitHub Bot) #653183e58e48ea8] - deps: update googletest to49495ea(Node.js GitHub Bot) #65317670b3665c0] - deps: cherry-pick libuv/libuv@e640dc9(ulofiai) #65118ca1c67b021] - deps: float ICU-23262 patch for icu78 (René) #646784ad043b0aa] - deps: enable AVX-512 OpenSSL asm with clang (Daniel Lemire) #6513696b4af109b] - deps: update googletest tod89aac5(Node.js GitHub Bot) #65153774f663c56] - dgram: don't swallow bind errors when callback is provided (armanmikoyan) #6260294b118d62e] - diagnostics_channel: validate before channel activation (Trivikram Kamat) #6531309788665bd] - dns: validate address type in lookupService (Lazizbek Ergashev) #6487815f95fc0e2] - dns: validate port range insetServers()(René) #6502137b9e9a154] - dns: fix crash on setServers with port 0 (Lazizbek Ergashev) #65009cd6205fa0d] - doc: update AHAFS reference link (Taeuk Ha) #654810e6f9ae42e] - doc: fix property names in os.networkInterfaces() example (Jihwan) #65469034a827b41] - doc: fix broken links in cli.md (Donghoon Kang) #65412eb364621d4] - doc: remove outdated WASI version fallback (이혜미) #65303b13f425bf8] - doc: fix broken GYP link in n-api.md (Donghoon Kang) #6541345c4011067] - doc: document that an empty OPENSSL_CONF skips config loading (Orgad Shaneh) #64949fde6776c5f] - doc: fix broken TLS security level example (soreavis) #65391290c1fec04] - doc: clarify socket destroyed behavior (Dayun) #65395a7e8269947] - doc: update outdated nodejs.org guide links (Donghoon Kang) #653947809f11249] - doc: clarify that ipv4 mapped to ipv6 are classified as ipv6 (Vedant Kulkarni) #6211764cd3a6e95] - doc: clarify how fs.Dirent file types are determined (soreavis) #645329b92fdce14] - doc: update security release prepare command (Rafael Gonzaga) #646996f9b9df3c1] - doc: clarify copyFile symlink behavior (T) #629412480acb550] - doc: document setRawMode write access on Windows (Erik Demaine) #63856a1e9c3a5db] - doc: add missing return types in fs.md (Chaseton Collins) #653074533572040] - doc: add missing return types in buffer.md (Yuya Inoue) #6530839ecedbbd2] - doc: fix lint clean command (greenhead) #652740b1fb8fcd8] - doc: fix typo in onboarding.md (서울민트초코) #652953165b5d38a] - doc: add missingadded:tags tofs.lchmod(Lazizbek Ergashev) #65283113b808e59] - doc: fix SQLite changeset constant descriptions (greenhead) #65265c3eb51d5a1] - doc: document open pull request limit (Matteo Collina) #65250d7accdcd52] - doc: document http2 header constants (Harjoth Khara) #64548f47111416f] - doc: create ai-guidelines and include to CONTRIBUTING (Rafael Gonzaga) #62105c3b120e737] - doc: update synopsis (Augustin Mauroy) #6517139f4c831fd] - doc: fix broken internal links (greenhead) #64901be25cdd69e] - doc: report proper return type on urlPattern.test (Brian Muenzenmeyer) #648311bf7737810] - doc: fix permission documentation examples (greenhead) #64897b7932e68a1] - doc: document sqlite parameter binding (Guilherme Araújo) #650895234a5169c] - doc: finalize statements in sqlite examples (Guilherme Araújo) #6508839ea929da7] - doc: document quic stopSending() and resetStream() (Issac) #648882ba198db73] - doc: clarify sqlite bare parameter default (Sumit Kumar Das) #62009314f9b200f] - doc: remove usage ofutil.inherits(Augustin Mauroy) #60817d82a61662c] - doc: fix grammar in worker_threads.md (이혜미) #6491344c0c8ff5b] - doc: clarify OpenSSL FIPS configuration (Filip Skokan) #649829b2ca70e0d] - doc: remove--expose-gcflag from CLI documentation (Dario Piotrowicz) #58909a0a12397b9] - doc: document ArrayBuffer support in pbkd2Sync (kyungrae2002) #64976b48699e077] - doc: correct default highWaterMark values (Yilong Li) #646170312ee133c] - esm: avoid super-linear data URL MIME regex (Sumit Kumar Das) #61951cd84d55c81] - esm: only register text format when enabled (Efe Karasakal) #64992c0a8ef611e] - esm: fix wasm import name in error message (이혜미) #64950e6c34f90c2] - events: inline iterationCondition hybrid dispatch closure (Szymon Łągiewka) #644736ee4b40c91] - events: inline createEvent hybrid dispatch closure (Szymon Łągiewka) #64473367549eed5] - fs: use sized reads for large files in readFileUtf8 (Shelley Vohr) #653288a5b1ae4c2] - fs: fix realpath of namespaced drive paths (Jason Zhang) #65378c9233b950d] - fs: fix glob early return skipping sibling entries (Srinu desetti) #64895bc54dd8905] - fs: pass symlink type in cp when filter is provided (Jerry Zhao) #62654fcb4333aca] - fs: allocate FSReqPromise stat arrays lazily (Samuel Attard) #63886c35876154e] - fs: fix out-of-bounds write in mkdtemp for long prefixes (Hierax_Umbra) #64770b269616936] - fs: treatstd::errc::permission_deniedasEPERMerror (Kirill Saied) #64698212fe77e76] - fs: add windowsHandle option to file streams (Kirill Saied) #6385175df6cb435] - http: improve performance with known-length calls to end() (Tim Perry) #6546648d9cd4a28] - http: cache maxHeaderPairs per header section (GetThatCookie) #6498804785c8f43] - http: fix keylog listener setup on existing agent sockets (Shani Singh) #650664b90031534] - http: emit drain on socket takeover and avoid stale HWM reuse (Naman Trivedi) #6499183a27559cd] - http2: adapt receive deferral for Node.js 24 (Matteo Collina) #65093f43bed0ecc] - http2: avoid uaf while receiving and sending rst_stream (esgor) #64166b42d664321] - inspector: avoid calling into JS from V8 interrupts (Joyee Cheung) #650286bf852197d] - lib: use bracket notation instead of startsWith/endsWith for single char (Taejin Kim) #61500151ca7e104] - lib: harden webidl dictionary member reads (Filip Skokan) #651157e8c2c9f44] - lib: use validateArray for array arguments (greenhead) #64959424fe2bc5a] - lib: add and test [EnforceRange] in webcrypto dictionaries (Filip Skokan) #650910529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #65024186e1b76e8] - meta: move targos to emeritus (Michaël Zasso) #65393b41b07c72a] - meta: add unified http api initiative (James M Snell) #65139f85b6ecd67] - meta: move one or more collaborators to emeritus (Node.js GitHub Bot) #651828f3d01bdce] - meta: add Aviv Keller to.mailmap(Aviv Keller) #65048cfad1d5b28] - meta: update sccache to 0.17.0 (René) #64985349c53c441] - module: report unreadable package.json (Paul Bouchon) #65223bd21e6706e] - module: cache nearest parent package.json per directory (Shelley Vohr) #65326961bd04370] - module: fix --check on ambiguous ESM files (Paul Bouchon) #65203f45ef73420] - net: handle undefined parent in _unrefTimer and _destroy (Shivay-98) #6464441c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #649745197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #654161722ddac28] - permission: enforce addon permission in GetLinkedBinding (Rafael Gonzaga) #65432dff2b675db] - process: validate resource stats array offsets (Archkon) #65098f277983e7b] - quic: changes for nghttp3_conn_close_stream2 (Marten Richter) #64574a4c770c78e] - quic: mark drain promise handled (James M Snell) #653192460b171c5] - quic: reset rejected HTTP/3 request streams with H3_REQUEST_REJECTED (trivenay) #6544218a7ccf302] - quic: write desired size needs update on maxstream (Marten Richter) #647689017f4a780] - quic: do not destroy incoming streams that have a consumer (trivenay) #65335ddc41c1ef4] - quic: fix wake up blob (Marten Richter) #6404488bee43d7c] - quic: convert incoming :status header to number (Hallison Pereira Melo) #63589cd776fe97c] - quic: fix infinite loop if STOP_SENDING received on a buffering stream (Tim Perry) #647154f6eda3c23] - repl: keep entries added while history file is loading (Mhayk Whandson) #64513cd1e6ce29b] - repl: add benchmarks (Aviv Keller) #645902ba740669d] - sea: avoid dangling CLI option pointers (Archkon) #64755ec5e2d6856] - sea: handle NUL bytes in asset keys (Archkon) #64773703b854293] - sea: reject trailing content in config JSON (Archkon) #64774a61a5fdd1c] - sqlite: prevent reentrant session.close() (Trivikram Kamat) #653496ae81be0a3] - sqlite: reject statement-less SQL in prepare() (Trevor Burnham) #65157043dfe4996] - sqlite: reject statement-less SQL in SQLTagStore (Trevor Burnham) #65157b8faee02e1] - sqlite: check null returns from sqlite value functions (Nora Dossche) #63288d6d2a71bee] - sqlite: validate maxSize argument in createTagStore() (Anshika Jain) #6379261a046309f] - sqlite: reject non-positive backup rates (Trivikram Kamat) #64893514e3f30fb] - sqlite: clear SQLTagStore bindings (Matteo Collina) #65041c1542255b8] - sqlite: bind Boolean (mike-git374) #62001cdb732beb5] - sqlite: fix undefined behaviour inSession::Changeset()(Nora Dossche) #63637fbe8861111] - sqlite: bind ArrayBuffer (mike-git374) #62061e3c6bd6bc8] - src: add missing vector include (Filip Skokan) #65622793cf69df8] - src: fix heap value deduplication in embedder graph (Ilyas Shabi) #64801ea5935b04c] - src: fix out-of-bounds write when transcoding odd-length ucs2 (nashit hayat) #6451222e5023f4d] - src: escape Windows environment variables in task runner (Antoine du Hamel) #65217a0f3c62bd9] - src: simplify c++ diagnostics channel API (James M Snell) #651588e831a3d2e] - src: make minor cleanup to permission checks (James M Snell) #65158968b2ca3a3] - src: use DictionaryTemplate for permission diag channel message (James M Snell) #6515818e16e7f8d] - src: cache permission strings (James M Snell) #65158c8625a4b6f] - src: add SetAbortHandler (Max H Fisher) #64684c990140d60] - src: match cmd.exe case-insensitively in task runner (Archkon) #64907d7463b9dbc] - src: reuse cached env strings in remaining files (Seongeun Lee) #65039b055a43b93] - src: expose Windows-only fs open flags (Kirill Saied) #647757f21e37496] - src: report why --enable-fips failed (Filip Skokan) #649798c11beae27] - src: update repeated use strings to env (James M Snell) #647609e2c477e26] - stream: normalize fused stateless transform results (Trivikram Kamat) #65367107e96dd41] - stream: encode whole chunks in TextEncoderStream (Matteo Collina) #65414164068279b] - stream: prevent share from eagerly draining source (Trivikram Kamat) #6533893d822bdc1] - stream: drain pending writes before broadcast end (Trivikram Kamat) #653346b8b9c362f] - stream: reuse unexposed managed read buffers (GetThatCookie) #649904ec4fab367] - stream: avoid duplicated endReadableNT scheduling (Matteo Collina) #6531086d1196ebf] - stream: decouple transform backpressure changes (Matteo Collina) #65143b8a7a75b19] - stream: reject pull on signal abort during flush (Trivikram Kamat) #65346386ed6a06d] - stream: avoid leaking consumers on signal failure (Trivikram Kamat) #6529974d53bd73b] - stream: use validateObject for zlib/iter params (greenhead) #650153a174ce16b] - stream: use validateNumber for BYOB reader options.min (greenhead) #65014859ea01cb2] - stream: consolidate non-op algorithm callbacks (Matteo Collina) #65138c577669825] - stream: cut promise churn in webstreams hot paths (Matteo Collina) #65138d631e910db] - stream: preserve falsy cancellation reasons (Trivikram Kamat) #64705f9c21eabbd] - stream: use validateBuffer for BYOB reader view (greenhead) #65046b89c8f5d1e] - stream: fix recursive WritableStream abort (Jeong SeokChan) #6482539e0457e86] - test: fix link-local dgram scope assertion (Filip Skokan) #656291433cf9d5b] - test: account for varied OpenSSL CCM final behaviours (Filip Skokan) #655427d135d24b7] - test: convert forEach to for of test-messageevent-brandcheck file (Nachiketa Pathak) #65279421ee11715] - test: use spawnSyncAndAssert in windowsHide test (Junsoo Ha) #65351929d5705bc] - test: remove test-debugger-run-after-quit-restart as flaky on macOS (Yuya Inoue) #65424f38f154c14] - test: simplify test-timers-interval-promisified.js (Donghoon Kang) #65322a98e27f2a9] - test: add Headers coverage and benchmark (Yagiz Nizipli) #6536538fdbb62aa] - test: deflake test-net-listen-ipv6only (sangwook) #6417306c7684b01] - test: use common/child_process spawnSync helpers (Junsoo Ha) #653776438c70004] - test: fix Linux debug skip in SEA test guard (구현우) #63751fe0e4f1b65] - test: avoid timer race in event loop delay test (Trivikram Kamat) #647286ff69baea8] - test: enforce exit code intest-http-server-stale-close(Antoine du Hamel) #65198ba87603016] - test: convert test-async-local-storage-bind to async loop (freida-code) #652708d6b89f454] - test: replaceforEach()withfor...ofin parallel tests (Phillip Markert) #65272a60572a7bb] - test: convert forEach to for in test-constant.js file (NIxxy25) #65271f82060c6ce] - test: use for-of instead of forEach (Felix P.) #652685ded71f9cc] - test: coverrealpathSyncresolving symlinks after a FIFO stat (Hendrik Liebau) #65113ac9835225e] - test: account for [EnforceRange] in test-webcrypto-prototype-pollution (Filip Skokan) #65173550d24277e] - test: update WPT for WebCryptoAPI to4c2fd05(Node.js GitHub Bot) #651502aa26559f0] - test: update WPT for urlpattern to4832db4(Node.js GitHub Bot) #65151d45c010108] - test: fix hidden error in test-http-server-stale-close.js (Meghan Denny) #59357881f8d092d] - test: avoid deadlock issue in pipeline http2 tests to fix flakiness (Tim Perry) #65079e4b1e3ee75] - test: allow half-open CONNECT tunnel sockets (Trivikram Kamat) #6497300f4240d48] - test: update passphrases to comply with the next OpenSSL FIPS mode (Filip Skokan) #65077cf7680efb7] - test: use libuv clock for immediate queue test (Trivikram Kamat) #64889b0c12772ff] - test: increase timeout in probe-failure-hang-during-evaluate (Joyee Cheung) #647197e279104b4] - test: update WPT for WebCryptoAPI to82c3d90(Node.js GitHub Bot) #64977ac11f88d16] - test,doc: cover and document multi-byte offset/size in randomFill (kyungrae2002) #6483467da38cada] - test_runner: match dotfiles in default coverage exclude (semimikoh) #63401b06c61a08f] - test_runner: print coverage and diagnostic info with dot reporter (mag123c) #614237cb9c9c126] - test_runner: use run options with isolation="none" (Sylvester Keil) #62269339acf4201] - test_runner: mock dual-package with conditional exports (Maruthan G) #62943e7a68bca08] - test_runner: add classname hierarchy for JUnit reporter (mag123c) #602206a248acefe] - test_runner: fix junit report on empty diagnostic (Lazizbek Ergashev) #65357d01dda79b6] - test_runner: do not tag-filter test file wrappers (Chemi Atlow) #6517032ead10ddd] - test_runner: fix env option validation (Jihwan) #64865b0ef155440] - tls: throw on invalid ALPNProtocols instead of aborting (Sankalp Thakur) #65076dcf65c50ce] - tls: fix authorized state on no-cert TLS1.3 client cert resumption (Tim Perry) #64677b0f54bda78] - tools: improve commit queue failure comment (Filip Skokan) #65433bc1f2718d5] - tools: fix max body length handler increate-release-proposal.sh(Antoine du Hamel) #65455bbe76516a9] - tools: bump brace-expansion in/tools/clang-format(dependabot[bot]) #6498467697debdf] - tools: make env variables consistent in cron jobs (Antoine du Hamel) #65168ac8a68ec92] - tools: only include fast-tracked and old enough PRs in CQ (Antoine du Hamel) #651976d9999fa2e] - tools: remove skip logic incommit-queue.sh(Antoine du Hamel) #6516260bfa1694e] - tools: bump js-yaml from 4.2.0 to 4.3.1 in /tools/lint-md (dependabot[bot]) #65129782748527e] - tools: bump js-yaml from 4.2.0 to 4.3.1 in /tools/eslint (dependabot[bot]) #65130dac257340f] - tools: fix GITHUB_TOKEN permissions for CQ workflow (Antoine du Hamel) #65192e624785846] - tools: use the read-only token when filtering PRs in CQ (Antoine du Hamel) #651697d9dcfaaa7] - tools: delay removal ofcommit-queuelabel (Antoine du Hamel) #651010d7c7936e7] - tools: move ncu config to global for commit queue (Filip Skokan) #651325e1db5a38a] - tools: prefilter commit queue metadata (Filip Skokan) #64343f41509b91d] - tools: lazy-abort failed PR merges in CQ (Antoine du Hamel) #65004ceb0e99acd] - tools: sync mk-ca-bundle.pl with curl (Archkon) #64753600663b23f] - tty: add raw-vt and io raw modes (Samuel Williams) #64140a40bfc742e] - typings: add signal_wrap internal binding types (Seongeun Lee) #65229b103a4a3b9] - typings: add diagnostics_channel typings (Seongeun Lee) #65227e64de34b89] - typings: add watchdog internal binding types (Seongeun Lee) #65228c57c83b4d1] - typings: add internal_only_v8 binding typeis (Donghoon Kang) #65071f15e8c9dcd] - typings: add credentials internal binding types (Donghoon Kang) #65036a500256b0b] - url: skip unused href reuse comparison (Yagiz Nizipli) #6536158390f8bec] - url: speed up WHATWG URL parsing (Yagiz Nizipli) #653617d5428c812] - url: speed up URLSearchParams (Yagiz Nizipli) #653638e2461d819] - url: bounds-check short Windows file URL paths (Archkon) #647889ffc0da90c] - url: handle unparsable serialized URLs in setters (Matteo Collina) #64651fa9d4e075d] - util: allow single-line format when break length is infinite (Hamid Reza Ghavami) #64238b68a7c3862] - util: fix OSC 8 hyperlink stripping in stripVTControlCharacters (Dushyant Singh Hada) #6431910cbb6dc00] - util: fix formatting of functions returned from getters (Richard Gibson) #6483964c20b449e] - util: use more primordials incomparisons.js(Ayoub Mabrouk) #61198cea9786de8] - util: preserve function names without source map names (Hiroki Osame) #6510835c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #649655858c2ba9a] - zlib: validate pledgedSrcSize for sync zstd (Archkon) #64601actions/node-versions (node)
v24.21.0: 24.21.0Compare Source
Node.js 24.21.0
pnpm/pnpm (npm:pnpm)
v11.27.0: pnpm 11.27Compare Source
Minor Changes
nodeDownloadMirrorscan now be set in the global config file (config.yaml) and through thePNPM_CONFIG_NODE_DOWNLOAD_MIRRORSenvironment variable, so a Node.js download mirror can be configured once for a machine instead of in every workspace #12124, #13611.Added a new setting
trustPolicyExcludePrune(default:false). When enabled,pnpm add,pnpm update, andpnpm removeprune the entries oftrustPolicyExcludeinpnpm-workspace.yamlthat the freshly written lockfile no longer resolves: versions that are gone are dropped (an entry is removed once none of its versions remain), and entries for packages that are no longer in the lockfile are removed too. Name patterns (@scope/*) are always kept. The cleanup is skipped when the install's lockfile does not cover the whole workspace (sharedWorkspaceLockfile: false), since entries another project still needs would look stale.Patch Changes
pnpm now reads the
packageManager,devEngines.packageManagerand runtime pins from the workspace root'spackage.jsonwhenlockfileDiris set. A project that moved its lockfile lost the pins it declared there #14633.Fixed
pnpm add -g,pnpm update -g, andpnpm remove -gmutating global bins or install directories after only partially reading an installed package group. If any declared package manifest is missing, malformed, or unreadable, pnpm now fails before activation or removal and leaves the existing global installation intact pnpm/pnpm#13796.fetch-timeoutnow limits how long a request may make no progress. The timer restarts on every chunk that arrives. A large download over a slow connection is no longer aborted while data is still coming in. A connection that stops delivering data still fails afterfetch-timeout#14604.pnpm peers checkno longer reports a peer dependency declared asworkspace:^,workspace:~, or a bareworkspace:as unmet. pnpm reported these as unmet whatever version the linked workspace project supplied #14770.A
readPackagehook that edits its argument in place no longer changes what a later install in the same command resolves. Adeprecatednotice read from the lockfile no longer carries over to another install either #13988.pnpm installnow auto-installs missing transitive peers when workspace projects share a dependency at different depths. This also removes incomplete duplicate peer contexts from the lockfile. Fixes pnpm/pnpm#14840.GitHub Actions updates now stop if an action reference changes while its versions are being resolved. Unrelated workflow edits are preserved.
GitHub Actions homepage links no longer expose server credentials. GitHub server URLs now require HTTPS, with HTTP allowed only for loopback hosts.
pnpm licenses listnow reports the runtime downloaded throughdevEngines.runtimewithonFail: "download". The command previously failed withERR_PNPM_UNSUPPORTED_PACKAGE_TYPE#14172.pnpm no longer creates a project
pnpm-lock.yamlwhendevEngines.packageManager.onFailisdownloadand lockfile writing is turned off withlockfile: falseor--no-lockfile. pnpm still switches to the pinned version #14728.A
registryor@scope:registryset in an.npmrcnow wins over the registry apnpm logincredential stored in the globalconfig.yamlpoints at. Previously, after logging in to one registry, installs in a project whose.npmrcnamed a private registry went to the logged-in registry instead. They now go to the registry the.npmrcnames #14614.A patch that gives a dependency a
preinstall,install, orpostinstallscript, or abinding.gyp, now runs that build. pnpm asks for build approval first, so the package is listed under "Ignored build scripts" until it is allowed to build. pnpm 12 ran nothing, and pnpm 11 ran it without asking #14648.Registries that share a host but differ by URL path — one JFrog Artifactory, Nexus, AWS CodeArtifact or GitLab Packages instance serving several repositories — now get a metadata cache directory each. Previously they shared one, so resolving a package from one of them could answer with another's versions, integrity hashes and tarball URLs and fail with
ERR_PNPM_TARBALL_URL_MISMATCH#13558.The URL scheme is part of the cache directory name too, so an
httpregistry can no longer hand its metadata — which can be rewritten in transit — to a resolution configured forhttpsat the same host.The first install after upgrading refetches registry metadata once. The package store is untouched.
pnpm cache viewnow labels each entry with the full registry URL. It printedregistry.npmjs.orgbefore and printshttps://registry.npmjs.org/now.pnpm cache list-registriesandpnpm cache listprint the new directory names. Scripts that parse either command need updating.Updated the embedded Node.js release keys to the current canonical
nodejs/release-keyslist.pnpm sbomnow omits package author fields when the manifest author name is empty or contains only whitespace pnpm/pnpm#14685. In a filtered or split workspace run, only a project with noauthorfield inherits the workspace root's author.pnpm sbom --sbom-format spdxnow writescreationInfo.createdwith whole seconds, such as2026-09-08T10:38:21Z. The timestamp carried fractional seconds, which strict SPDX consumers rejected #14684.Windows filesystem operations now retry permission errors for up to one second. Permanent permission errors previously delayed failure by a minute. Sharing and lock violations retain their one-minute retry budget pnpm/pnpm#14682.
pnpm now writes
node_modules/.package-map.jsononly whennodeExperimentalPackageMapis enabled. Nothing reads the file without that setting. An install that stops writing the map removes the one a previous install left.pnpm now unpacks a downloaded runtime archive into a randomly named directory inside the store. It previously used a predictable path, where another user of a shared store could plant a symlink and redirect the write outside the store (GHSA-vwc7-r8mq-g2x9).
Platinum Sponsors
Gold Sponsors
v11.26.0: pnpm 11.26Compare Source
Minor Changes
Catalogs can now resolve workspace dependencies through the
workspace:protocol.pnpm removeandpnpm updatenow accept--trust-lockfile,--no-trust-lockfile,--trust-policy,--trust-policy-exclude, and--trust-policy-ignore-after.pnpm removechecks the whole lockfile against the active policies unless--trust-lockfileis set.Added
pnpm change checkfor CI validation of package versions against theversioning.epicsbands andversioning.fixedgroups inpnpm-workspace.yaml.Patch Changes
Fetch and tarball errors and retry logs now hide URL credentials, query strings, and fragments that could expose secrets.
Fixed a race during config dependency updates that could redirect a lockfile write through a symlink #14322.
pnpm add --allow-build=!<pkg>now correctly denies builds, including in global installs.pnpm approve-builds <pkg>andpnpm approve-builds !<pkg>now save decisions even when the package is not awaiting approval, with a warning #14067.Fixed
pnpm audit --fixfailing without a value or when followed by another flag.pnpm audit --fix=overridenow respectssaveExactandsavePrefixwhen writing overrides #13261, #11523.pnpm auditnow excludes ignored advisories from vulnerability totals and severity counts, and reports them separately #14535.pnpm deployno longer requiresinjectWorkspacePackages. If a workspace dependency's peer has multiple possible versions, deployment reportsERR_PNPM_DEPLOY_AMBIGUOUS_PEERwith the conflicting versions. Pin the peer withoverridesto deploy without injection #9386.Fixed concurrent installs sharing a store occasionally failing with an
ENOENTerror while importing a package file #14353.Fixed installation failures when a linked local dependency provides a peer dependency also provided by an ancestor, including with
pnpm deploy --legacy.pnpm install --node-linker=hoistedno longer downloads skipped optional dependencies whennode_modulesalready exists #14139.Fixed
pnpm installrejecting a symlinked lockfile when config dependencies are unchanged. Updates to config dependencies also preserve lockfiles with a byte order mark. Writes through symlinked lockfiles remain blocked #14372.pnpm installnow relinks workspace packages whenpublishConfig.linkDirectorychanges. Frozen installs require the lockfile to be regenerated #14488.Auto-installed optional peers now satisfy their declared range even when the workspace root uses a version outside that range #13867.
Fixed global virtual store paths for dependency cycles to consistently account for the runtime engine when dependencies have allowed builds #14341.
Standalone installations now preserve the bundled
node-gypfiles needed to build native dependencies.Downloaded runtimes are now available to dependency lifecycle scripts during installation.
Node.js downloads from
nodeDownloadMirrorsnow use URL-scoped npm credentials, including bearer tokens, basic auth, andtokenHelper#14334.Fixed
globalDirandglobalBinDirhandling in global configuration and environment variables, including~/expansion. This fixespnpm add -gfailing afterpnpm config set -g global-bin-dir#14336.The JavaScript pnpm can again switch to the project's pinned pnpm version on hosts without a matching native binary. If the requested version requires an unavailable native binary, the error now identifies the unsupported host #13622.
Global
pnpm configcommands now skip project package manager version switching, allowing authentication to be configured before downloading the pinned version #14463.pnpm self-update,pnpm with, and automatic version switching no longer wait through registry retries when a configured registry has no signatures andregistry.npmjs.orgis unavailable #14483.Fixed argument forwarding on Windows with
shellEmulatorenabled. Trailing backslashes, line breaks, and literal shell expressions are preserved #14548.Relative
scriptShellpaths now resolve from the workspace root. Bare command names such asbashstill usePATH#14422.pnpm importnow preserves the project-local lockfile whenlockfileDirpoints elsewhere and restores the destination lockfile on failure. Branch lockfile imports leave the shared lockfile unchanged #14563.catalogModeand--save-catalogno longer move local paths, tarballs, orworkspace:<path>specifiers into catalogs #14437.--side-effects-cache,--no-side-effects-cache, andPNPM_CONFIG_SIDE_EFFECTS_CACHEnow toggle only the local cache, preserving any remote cache configured insideEffectsCache.pnpm unpublishnow handles registry two-factor authentication challenges through web authentication or a one-time password prompt #14464.pnpm outdatedandpnpm updatenow follow GitHub Actions references using self-repository syntax, such asuses: $/.github/actions/setup.pnpm removenow accepts--unsafe-perm.Platinum Sponsors
Gold Sponsors
typescript-eslint/typescript-eslint (typescript-eslint)
v8.70.0Compare Source
🩹 Fixes
❤️ Thank You
See GitHub Releases for more information.
You can read about our versioning strategy and releases on our website.
vitejs/vite (vite)
v8.3.0Compare Source
Features
server.watch(#23133) (1b5cfe3)tsconfigoption (#23310) (93164c3)applyToEnvironmenthook (#23191) (fdef04f)import.meta.ROLLDOWN_FILE_URL_*for assets in JS (#22888) (4366ac4)import.meta.ROLLDOWN_FILE_URL_*for other plugins (#22894) (e38f29e)Bug Fixes
node_modulespath segments as dependencies (fix #17467) (#23437) (ef0dc17)resolveFileUrlhook (#23422) (e8d6a4d)import.meta.hot.invalidatein virtual module (#23171) (6162968)Performance Improvements
Miscellaneous Chores
@e18e/eslint-plugin(#23357) (f794133)PluginContainerOptions(#23382) (ee64401)sortImports(#23319) (97ad042)Code Refactoring
esbuildPlugin(#23381) (f40efef)__VITE_ASSET__(#22886) (a6c08e1)urlIdofimport.meta.ROLLDOWN_FILE_URLin wasm plugin (#22962) (92bd2a7)Tests
renderBuiltUrlchange changes hash (#23118) (0291408)Beta Changelogs
8.3.0-beta.1 (2026-09-07)
See 8.3.0-beta.1 changelog
8.3.0-beta.0 (2026-09-02)
See 8.3.0-beta.0 changelog
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
61386e42c719076ded70